Tag Archives: CWE- 553

CWE-553 – Command Shell in Externally Accessible Directory

Read Time:22 Second

Description

A possible shell file exists in /cgi-bin/ or other accessible directories. This is extremely dangerous and can be used by an attacker to execute commands on the web server.

Modes of Introduction:

– Implementation

 

 

Related Weaknesses

CWE-552

 

Consequences

Confidentiality, Integrity, Availability: Execute Unauthorized Code or Commands

 

Potential Mitigations

Phase: Installation, System Configuration

Description: 

Remove any Shells accessible under the web root folder and children directories.

CVE References