|
BNB Survey.cgi Metacharacter Vulnerability
Big Nose Bird provides a free script, Survey.cgi, which provides a simple "Web Survey" function. This script does poor input checking, inappropriately allowing shell metacharacters (such as the pipe "|" character, input and output characters ">" and "<", etc) in user supplied data. This could lead to an elevation of user privileges by allowing an attacker to execute shell commands with the privileges of the web server. |
|
|
Privacy Statement |