Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-2347
CVE-2004-2347
Description
blog.cgi in Leif M. Wright Web Blog 1.1 and 1.1.5 allows remote attackers to execute arbitrary commands via shell metacharacters such as '|' in the file parameter of ViewFile requests.
Affected products
2cpe:2.3:a:leif_m._wright:web_blog:1.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:leif_m._wright:web_blog:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:leif_m._wright:web_blog:1.1.5:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.securityfocus.com/archive/1/352303nvdExploit
- www.securityfocus.com/bid/9539nvdExploitPatch
- secunia.com/advisories/10776/nvdVendor Advisory
- leifwright.com/scripts/Blog.htmlnvd
- www.osvdb.org/3793nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/15019nvd
News mentions
0No linked articles in our index yet.