Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
CVStrac Remote Arbitrary Code Execution exploit Aug 05 2004 05:57PM
Richard Ngo (rtngo yahoo com)
Hi, Im Richard Ngo, this is the first time i report an
exploit and found a remote exploit that could allow
arbitrary code execution in CVStrac.

sample exploit

filediff?f=CVSROOT/rcsinfo&v1=1.1&v2=1.2;w;

All versions vulnerable. I have not contacted
cvstrac.org since i cant find their email addres...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus