exploit-db-mirror/exploits/multiple/remote/21801.txt
Offensive Security 36c084c351 DB: 2021-09-03
45419 changes to exploits/shellcodes

2 new exploits/shellcodes

Too many to list!
2021-09-03 13:39:06 +00:00

9 lines
No EOL
567 B
Text

source: https://www.securityfocus.com/bid/5725/info
DB4Web is an application server that allows read and write access to relational databases and other information sources, via the web. The application is available for Windows, Linux, and various Unix platforms.
By requesting a specially crafted URL, it is possible to initiate a TCP connect from the vulnerable server to a remote IP address and arbitrary port.
The server will then produce a debug page, which can be used to determine port status on the scanned host.
http://127.0.0.1/DB4Web/172.31.93.30:22/foo