exploit-db-mirror/platforms/php/webapps/22336.txt
Offensive Security 5e2fc10125 DB: 2016-09-03
2016-09-03 13:13:25 +00:00

7 lines
No EOL
533 B
Text
Executable file

source: http://www.securityfocus.com/bid/7030/info
A vulnerability has been reported in PHPPing that may allow remote attackers to execute commands on vulnerable systems.
The vulnerability exists in the index.php script file. Some variables are not properly sanitized of malicious shell metacharacters. An attacker can exploit this vulnerability by executing the PHPPing script and include malicious shell metacharacters as values for various parameters.
http://www.target.com/phpping/index.php?pingto=www.test.com%20|%20dir