guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".
Link | Tags |
---|---|
http://www.securityfocus.com/archive/82/27296 | mailing list exploit vendor advisory |
http://www.securityfocus.com/bid/776 | exploit vdb entry patch vendor advisory |
http://www.securityfocus.com/archive/1/33674 | mailing list vendor advisory |
http://www.securityfocus.com/archive/82/27560 | mailing list vendor advisory |