Extropia WebBanner Input Validation...

- AV AC AU C I A
发布: 2000-06-14
修订: 2025-04-13

Extropia WebBanner is an open-sourced perl cgi utility that allows a webmaster to display banners randomly. One of its components, index.cgi, is vulnerable to an input validation vulnerability. It passes a user-inputtable http variable (html_file) to the open() call without checks for metacharacters. As a result, it is possible to execute arbitrary commands on the target host and gain remote access with the priviliges of the webserver.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息