Lucene search

K
exploitdbVanja HrusticEDB-ID:19747
HistoryFeb 08, 2000 - 12:00 a.m.

Zeus Web Server 3.x - Null Terminated Strings

2000-02-0800:00:00
Vanja Hrustic
www.exploit-db.com
28

AI Score

7.4

Confidence

Low

source: https://www.securityfocus.com/bid/977/info

Appending "%00" to the end of a CGI script filename will permit a remote client to view full contents of the script if the CGI module option "allow CGIs anywhere" is enabled. Scripts located in directories which are designated as executable (eg. \cgi-bin) are not vulnerable to this exploit.

http ://target/script.cgi%00

"%00" may be replaced with "%G0", "%W0", "%EW", "%FG", "%UW", or "%VG" in order to achieve the same results. 

AI Score

7.4

Confidence

Low

Related for EDB-ID:19747