CVE-2007-3572 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 8.4% (pctl 95)
Patch early
A public exploit exists.
Description
Incomplete blacklist vulnerability in cgi-bin/runDiagnostics.cgi in the web interface on the Yoggie Pico and Pico Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the param parameter, as demonstrated by URL encoded "`" (backtick) characters (%60 sequences).
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 8.38% — more likely to be exploited than 95% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-07-05 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| yoggie | pico |
| yoggie | pico pro |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Yoggie Pico and Pico Pro Backticks - Remote Code Execution | 2007-07-02 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2007-07/0020.html
- http://archives.neohapsis.com/archives/fulldisclosure/2007-07/0092.html
- http://osvdb.org/37808
- http://secunia.com/advisories/25902
- http://www.securityfocus.com/bid/24743
- http://www.vupen.com/english/advisories/2007/2417
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35208
- http://archives.neohapsis.com/archives/fulldisclosure/2007-07/0020.html
- http://archives.neohapsis.com/archives/fulldisclosure/2007-07/0092.html
- http://osvdb.org/37808
- http://secunia.com/advisories/25902
- http://www.securityfocus.com/bid/24743
- http://www.vupen.com/english/advisories/2007/2417
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35208
→ the Explorer · watch your stack · NVD