Bajie 0.78 - Arbitrary Shell Command Execution

EDB-ID:

20639


Author:

joetesta

Type:

remote


Platform:

Multiple

Date:

2001-02-15


Become a Certified Penetration Tester

Enroll in Penetration Testing with Kali Linux , the course required to become an Offensive Security Certified Professional (OSCP)

GET CERTIFIED

source: https://www.securityfocus.com/bid/2389/info

Requesting a specailly crafted URL containg arbitrary code, can be exected on a Unix system running Bajie Webserver. Any arbitrary commands appended to a malicious URL after the ';' will be executed as an independent job. 

http://target/bin/test.txt;%20[shell command]