CVE-2007-6176

Publication date

2007-11-30 00:00:00

Family

mitre

State

PUBLISHED

Description

kb_whois.cgi in K+B-Bestellsystem (aka KB-Bestellsystem) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) domain or (2) tld parameter in a check_owner action.