PHP-CGI Arguement Injection Exploit - CVE-2012-1823

Опубликовано: 15 Октябрь 2024
на канале: Darren Martyn
4,742
1

This demo shows how we can exploit the infamous PHP-CGI Arguement Injection vulnerability in a number of ways. Using the commandline tool "POST" from lwp-requests, using a custom written Python exploit I wrote, or by simply using Metasploit.

Music in the demo is by Blackmail House - soundcloud.com/blackmail-house and is used with permission, under the "I buy the band members a case of beer" licence.

The article and exploit code may be found at http://insecurety.net/?p=705