Greg Matthews Classifieds.cgi Hidden...

- AV AC AU C I A
发布: 1998-12-15
修订: 2025-04-13

Classifieds.cgi is a perl script (part of the classifieds package by Greg Matthews) which provides simple classified ads to web sites. Due to improper input validation it can be used to execute any command on the host machine, with the privileges of the web server. If the attacker can submit a command to run as a hidden variable that command will be executed. Normally this variable is reserved for the mail program and is accessed from an HTML page with the following piece of code: <input type="hidden" name="mailprog" value="/usr/sbin/sendmail">

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息