[24818] in bugtraq

home help back first fref pref prev next nref lref last post

dcshop.cgi anybody can delete *.setup for database

daemon@ATHENA.MIT.EDU (pokleyzz sakamaniaka)
Mon Mar 25 15:36:39 2002

Date: 25 Mar 2002 09:10:52 -0000
Message-ID: <20020325091052.31868.qmail@mail.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: pokleyzz sakamaniaka <pokleyzz@hotmail.com>
To: bugtraq@securityfocus.com



cgi-pl in dcshop beta  (http://www.dcscripts.com) 
allow user to using nullbyte character for variable if 
using multipart/form data type form.
Using curl (http://curl.haxx.se/libcurl/) :

curl -F database=@test.txt http://host/cgi-
bin/dcshop.cgi

which test.txt contain databasename.setup[nullbyte]
will couse database.setup file being deleted

home help back first fref pref prev next nref lref last post