Multiple Vendor whois CGI...

- AV AC AU C I A
发布: 1999-11-09
修订: 2025-04-13

Whois scripts provide InterNIC lookup services via HTTP. The vulnerable scripts include versions of Matt's Whois and CGI City Whois. Older versions of these fail to filter metacharacters, allowing execution of arbitrary commands by embedding the commands in the domain name to lookup. Specifically, the UNIX command separation character ";" can be used to execute commands. Successful exploitation of this vulnerability would allow an attacker to execute commands with the privileges of the web server process, which could result in retrieval of sensitive information, web defacements, etc.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息