WebWho+ Remote Command Execution...

- AV AC AU C I A
发布: 1999-12-26
修订: 2025-04-13

WebWho+ is a free cgi script written by Tony Greenwood for executing whois queries via the www. Though it does perform checks for shell escape characters on some parameters, it misses the 'type' variable and allows for malicious input to be sent to a shell. It is possible to execute arbitrary commands on a webserver running WebWho+ v1.1 with the uid of the webserver (usually nobody).

0%
暂无可用Exp或PoC
当前有0条受影响产品信息