Exploit Hylafax 4.0 pl2 Faxsurvey - Remote Command Execution

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
20462
Проверка EDB
  1. Пройдено
Автор
TOM
Тип уязвимости
REMOTE
Платформа
UNIX
CVE
cve-1999-0262
Дата публикации
1998-08-04
Код:
source: https://www.securityfocus.com/bid/2056/info

Hylafax is a popular fax server software package designed to run on multiple UNIX operating systems. Unpatched version of Hylafax ship with an insecure script, faxsurvey, which allows remote command execution with the privileges of the web server process. This can be exploited simply by passing the command as a parameter to the script - see exploit. Consequences could include web site defacements, exploiting locally accessible vulnerabilities to gain further privileges, etc. 


http://target.host/cgi-bin/faxsurvey?/bin/cat%20/etc/passwd
 
Источник
www.exploit-db.com

Похожие темы