Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

BNB Survey.cgi Metacharacter Vulnerability

Big Nose Bird provides a free script, Survey.cgi, which provides a simple "Web Survey" function. This script does poor input checking, inappropriately allowing shell metacharacters (such as the pipe "|" character, input and output characters ">" and "<", etc) in user supplied data. This could lead to an elevation of user privileges by allowing an attacker to execute shell commands with the privileges of the web server.







 

Privacy Statement
Copyright 2009, SecurityFocus