PWC.CGI Syslog Format String Vulnerability...

- AV AC AU C I A
发布: 2001-03-23
修订: 2025-04-13

A remote format string vulnerability exists in pwc.cgi, a script designed to permit administrators to change user passwords remotely via a browser. Due to a failure to properly validate user-supplied input argumenting a call to syslog(), it is possible for a remote attacker to supply malicious input to the script which contains hostile shellcode. Properly exploited, the supplied code will execute with the privilege level of the webserver process.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息