Bugtraq mailing list archives

Active Perl path reveal


From: antoan miroslavov <shaltera () yahoo com>
Date: 29 Dec 2001 18:53:39 -0000



I recently found this exploit in Active Perl for 
Windows.If you request name with .pl extension 
which doesn't exist in CGI-BIN Perl Interpreter returns 
an error:

CGI Error
The specified CGI application misbehaved by not 
returning a complete set of HTTP headers. The 
headers it did return are:

Can't open perl script "C:\Inetpub\wwwroot\cgi-
bin\link1s.pl": No such file or directory

Antoan Miroslavov


Current thread: