Ranson Johnson mailto.cgi Piped...

- AV AC AU C I A
发布: 2000-09-11
修订: 2025-04-13

The value of the 'emailadd' variable in Ranson Johnson's Combination Mail-to and Credit Card Orderform is used in conjunction with a piped open. This value is supplied by users filling out the form. This opens up the possibility of remote command execution with the privilege level of the web server by entering specially crafted values into the 'emailadd' field on the form.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息