Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

phf Remote Command Execution Vulnerability

Solution:
This cgi-bin call, along with any others that are unused, should be removed. A patched version of the escape_shell_cmd() function is available as part of later httpd distributions. This can be obtained at: http://hoohoo.ncsa.uiuc.edu/beta-1.5

Apache should be upgraded immediately.








 

Privacy Statement
Copyright 2008, SecurityFocus