Description
Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via shell metacharacters (a | pipe character) provided as arguments to batch (.bat) or .cmd scripts, which are sent unfiltered to the shell interpreter, typically cmd.exe.
Remediation
References
Related Vulnerabilities
WordPress Plugin Tera Charts Multiple Local File Inclusion Vulnerabilities (0.1)
MediaWiki Missing Authorization Vulnerability (CVE-2021-30155)
Oracle Application Server CVE-2006-3706 Vulnerability (CVE-2006-3706)
WordPress Plugin All-in-One WP Migration Remote Code Execution (2.0.2)
WordPress Plugin Count per Day Search Bar Cross-Site Scripting (3.2.2)