[5830] in bugtraq

home help back first fref pref prev next nref lref last post

Re: CGI security hole in EWS (Excite for Web Servers)

daemon@ATHENA.MIT.EDU (carson@TLA.ORG)
Thu Dec 18 20:49:09 1997

Date: 	Thu, 18 Dec 1997 20:09:36 -0500
Reply-To: carson@tla.org
From: carson@TLA.ORG
X-To:         Marc Merlin <marc_merlin@MAGIC.METAWIRE.COM>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To:  <19971217230446.16473@moremagic.metawire.com>

The _really_ funny thing is that EWS 1.0P1 does _not_ appear to be
vulnerable. It looks like someone who shouldn't have been let near the
code decided to "enhance" it.

--
Carson Gaspar -- carson@cs.columbia.edu carson@tla.org carson@cugc.org
http://www.cs.columbia.edu/~carson/home.html
Queen Trapped in a Butch Body

home help back first fref pref prev next nref lref last post