Dispair远程命令执行漏洞

Dispair远程命令执行漏洞

漏洞ID 1106890 漏洞类型 输入验证
发布时间 2002-07-30 更新时间 2005-10-20
图片[1]-Dispair远程命令执行漏洞-安全小百科CVE编号 CVE-2002-1868
图片[2]-Dispair远程命令执行漏洞-安全小百科CNNVD-ID CNNVD-200212-706
漏洞平台 CGI CVSS评分 10.0
|漏洞来源
https://www.exploit-db.com/exploits/21679
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200212-706
|漏洞详情
Dispair0.1和0.2版本存在漏洞。远程攻击者借助某些表单字段执行任意shell命令。
|漏洞EXP
source: http://www.securityfocus.com/bid/5392/info

Dispair fails to sufficiently validate user-supplied input before it is passed to the shell via the Perl open() function. Remote attackers may potentially exploit this issue to execute arbitrary commands on the underlying shell with the privileges of the webserver process.

http://target/cgi-bin/dispair.cgi?file=fiddle&view=%0A/usr/bin/id
|参考资料

来源:BID
名称:5392
链接:http://www.securityfocus.com/bid/5392
来源:XF
名称:dispair-execute-commands(9787)
链接:http://www.iss.net/security_center/static/9787.php

相关推荐: Jetty Unspecified Denial Of Service Vulnerability

Jetty Unspecified Denial Of Service Vulnerability 漏洞ID 1098746 漏洞类型 Unknown 发布时间 2004-03-18 更新时间 2004-03-18 CVE编号 N/A CNNVD-ID N/A…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享