mailing list archives
From: Niels Heinen <niels () SAFEMODE ORG>
Date: Wed, 13 Sep 2000 21:38:34 +0200
Title : MultiHTML vulnerability.
Description : Retrieve files from the server.
Vendor status : Notified and a new (not much improved) script is
Short description of the tool:
MultiHTML allows you to put an SSI call where you want the HTML file to
The SSI executes the MultiHTML program which displays whatever HTML file
you have it set to
display. The main reason i'm posting this is because of the fact that
this script is offerd
by many lets-expand-our-cgi-bins-to-make-us-look-good isp's.
The cgi script checks the extentions of the requested file to see if it
is ok. This easily can be
tricked by using %00 ( Olaf Kirch )
further their is no dcumentroot specified in the script so we do not
need to use the ../../ here
because their is access to every directory on the system in question
(lame). Even if their was a
documentroot and they would filter the dots then you would have to make
sure that the script does
not contain any higher directory's. Because the open(FILE, "$multi")
functions in the script makes
it easy to bypass .htaccess files.
Be a man and learn how to use ssi without a script. Or beg someone to
write a new one ;)
- MultiHTML vulnerability Niels Heinen (Sep 14)