[5830] in bugtraq
Re: CGI security hole in EWS (Excite for Web Servers)
daemon@ATHENA.MIT.EDU (carson@TLA.ORG)
Thu Dec 18 20:49:09 1997
Date: Thu, 18 Dec 1997 20:09:36 -0500
Reply-To: carson@tla.org
From: carson@TLA.ORG
X-To: Marc Merlin <marc_merlin@MAGIC.METAWIRE.COM>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To: <19971217230446.16473@moremagic.metawire.com>
The _really_ funny thing is that EWS 1.0P1 does _not_ appear to be
vulnerable. It looks like someone who shouldn't have been let near the
code decided to "enhance" it.
--
Carson Gaspar -- carson@cs.columbia.edu carson@tla.org carson@cugc.org
http://www.cs.columbia.edu/~carson/home.html
Queen Trapped in a Butch Body