|
Linux Directory Penguin Traceroute Perl Script Arbitrary Command Execution Vulnerability
Penguin traceroute.pl is a freely available, open source script for tracing network hops from a web server. It is distributed by Linux Directory. The Penguin traceroute script does not adequately filter special characters. This makes it possible for a remote user to embed commands into a request using special characters such as the ';' or '|' characters. The embedded command would be executed with the permissions of the web browser. |
|
|
Privacy Statement |