Dream Catchers Book of Guests CGI...

- AV AC AU C I A
发布: 2001-10-30
修订: 2025-04-13

Book of Guests is a CGI script used to maintain a web based guestbook. The script fails to properly validate user-supplied CGI parameters, which are used to send email via a shell command. Maliciously formed URLs submitted to the script may contain shell commands which will be run with the privilege level of the webserver (ie 'nobody').

0%
暂无可用Exp或PoC
当前有0条受影响产品信息