CWE-553Variant

Command Shell in Externally Accessible Directory

Incomplete in the CWE catalog · 1 CVE mapped

1
CVEs mapped
8.6
Median CVSS
What it is

A possible shell file exists in /cgi-bin/ or other accessible directories. This is extremely dangerous and can be used by an attacker to execute commands on the web server.

Recent examples
8.6cvss
CVE-2025-66620

Columbia Weather Systems MicroServer Command Shell in Externally Accessible Directory

⚡ An unused webshell in MicroServer is a ticking time bomb for admins! This vulnerability allows unlimited login attempts, making it alarmingly easy for attackers to slip in undetected. 🔥 Think of it like a hotel with a staff door that never gets locked; anyone with a key can waltz in, and once inside, they can rummage through sensitive guest information or even change the locks permanently. 🏨 If an attacker gains admin access, they could establish reverse shells for continuous access, modify or delete critical data, or even turn the server into a puppet for their malicious plans. The worst part? It's like handing over the keys to your entire operation without a second thought!

HIGH
0%
epss
The record
Technical detail
CWE ID
CWE-553
Abstraction
Variant
Structure
Simple
Status
Incomplete