VDB

GCVE-110-CERTCC-2023-947701

GCVE-110-CERTCC-2023-947701
Advisory Published
Vulnetix · Advisory published August 7, 2023
### Overview Freewill Solutions IFIS new trading web application version 20.01.01.04 is vulnerable to unauthenticated remote code execution. Successful exploitation of this vulnerability allows an attacker to run arbitrary shell commands on the affected host. ### Description Freewill Solutions IFIS new trading web application passes a user controlled variable directly to a shell_exec function call on a specific report page. To exploit the vulnerability, an attacker can add shell meta characters to the user controlled variable so that the application executes attacker specified commands. ### Impact An attacker with access to the applications web interface can execute code on the remote host. This level of access allows for complete compromise of the affected machine. ### Solution The CERT/CC is currently unaware of a practical solution to this problem. ### Acknowledgements Thanks to Sameer Mohite (Mandiant) for reporting the vulnerability. This document was written by Kevin Stephens.

Browse GCVE Records

74,496 records in the GCVE database · Updated July 23, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›