[22721] in bugtraq
Intershop4
daemon@ATHENA.MIT.EDU (MegaHz)
Mon Sep 24 13:12:39 2001
Message-ID: <007801c1451a$2e619d60$0100a8c0@cytanet.com.cy>
From: "MegaHz" <admin@cyhackportal.com>
To: <bugtraq@securityfocus.com>
Date: Mon, 24 Sep 2001 19:58:46 +0300
MIME-Version: 1.0
Content-Type: text/plain;
charset="iso-8859-7"
Content-Transfer-Encoding: 7bit
Hi..,
I was checking out a site using that run's INTERSHOP 4 by
http://www.virtual-it.com.cy , hoping to find out some bugs,,,
and I found this:
https://www.xxxxxxxx.com/cgi-bin/buy.storefront/3baecb4a00025ad227a4c30e9501
0642/winnt/cmd.exe?/c+dir+c:\
or
https://www.xxxxxxxxxx.com/cgi-bin/buy.storefront/3baecb4a00025ad227a4c30e95
010642/hi/hi
It does the same think ( It does nothing) anybody can help me out to find
any bugs in order to help that company improve that software ?
Thanks..
====================================================
Andreas Constantinides (MegaHz)
Owner - Admin of cHp - http://www.cyhackportal.com
megahz@cyhackportal.com
====================================================