peter bassill · operator
$ cve CVE-2007-3572 JSON

CVE-2007-3572 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 8.4% (pctl 95)

Patch early

A public exploit exists.

Description

Incomplete blacklist vulnerability in cgi-bin/runDiagnostics.cgi in the web interface on the Yoggie Pico and Pico Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the param parameter, as demonstrated by URL encoded "`" (backtick) characters (%60 sequences).

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS8.38% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2007-07-05
Last modified2026-06-16

Affected (2)

VendorProduct
yoggiepico
yoggiepico pro

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD