TUCoPS :: Web BBS :: etc :: wayboard.htm

Way Board null character exploit
Vulnerability

    Way board

Affected

    Way board

Description

    'UkR-XblP' found following.  Way-board is a popular korean  board.
    Through this bug you can see any files, bug works on every  system
    were perl is installed.   "%00" - means hex  symbol of the end  of
    the line, used in C,C++ and perl.  Exploit:

        http://www.victim.com/way-board/way-board.cgi?db=url_to_any_file%00

Solution

    Nothing yet.

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH