Solution : Modify the affected CGI scripts so that they properly escape arguments.
If you don’t have access to the code base to change you can stick a WAF in front of the server e.g. Fortigate
![](https://pariswells.com/blog/wp-content/uploads/2023/08/image.png)
Solution : Modify the affected CGI scripts so that they properly escape arguments.
If you don’t have access to the code base to change you can stick a WAF in front of the server e.g. Fortigate