Posted by Marshall Whittaker on Jun 07
Hello,
I am willing to sell a new attack vector I have devised. The proof of
concept code you will receive has the ability to arbitrarily upload files to
a webserver (tested on Apache), running linux with the well known perl read
pipe vulnerability in many web CGI applications. This issue can also be
leveraged through PHP LFI and RFI attacks, and through almost any other
remote command execution vulnerability. The code has been tested on BSD,…




