Zeus Web Server Null Terminated...

- AV AC AU C I A
发布: 2000-02-08
修订: 2025-04-13

Appending "%00" to the end of a CGI script filename will permit a remote client to view full contents of the script if the CGI module option "allow CGIs anywhere" is enabled. Scripts located in directories which are designated as executable (eg. \cgi-bin) are not vulnerable to this exploit.

当前有1条漏洞利用/PoC
当前有0条受影响产品信息