Webboard: 3.1.12 search.cgi remote gaining shell access exploit fix

2001-05-03 Thread Alexander Barkov
Author: Alexander Barkov Email: [EMAIL PROTECTED] Message: Thanks. This fixed in 3.1.13 sources. Bad news. I just check your very recent search.c v1.23 via WWW cvs and see that you add tmplt= variable parsing there. Previous buffer overflow (I post the patch for) overflows data segment and

Webboard: 3.1.12 search.cgi remote gaining shell access exploit fix

2001-04-20 Thread Andrey A. Chernov
Author: Andrey A. Chernov Email: [EMAIL PROTECTED] Message: Please don't post in Russian here... Ok. Bad news. I just check your very recent search.c v1.23 via WWW cvs and see that you add tmplt= variable parsing there. Previous buffer overflow (I post the patch for) overflows data segment

Webboard: 3.1.12 search.cgi remote gaining shell access exploit fix

2001-04-19 Thread Andrey A. Chernov
Author: Andrey A. Chernov Email: [EMAIL PROTECTED] Message: Íàäî åù¸ ïðîâåðèòü âñå ìåñòà, ãäå ïàðñèòñÿ token. Ñì. îïèñàíèå àíàëîãè÷íîãî áàãà íà http://www.void.ru/news/0103/19.html Reply: http://search.mnogo.ru/board/message.php?id=2054 ___ If you want