WEB_CGI ws_mail.cgi access

 

Code: p1000

Severity: Notice

 

Description: This event is generated when an attempt is made to access ws_mail.cgi on an internal web server. This may indicate an attempt to exploit a remote command execution vulnerability in cgiCentral WebStore 400 4.14.

Impact: Execution of arbitrary code. An attacker must be an authenticated WebStore administrator to successfully execute this exploit.

Corrective: It is unknown if this vulnerability was fixed with WebStore 4.15. Contact the vendor, RDC Software (http://www.ratite.com/) for more information.