| |
MIVA® SECURITY: Vulnerability in htmlscript
by Ivo Truxa, 09/11/2000
This is a security flow in the old Htmlscript, it means versions prior 3.00. It allows an intruder to break out of the sandbox and access files in the root of the server. The example shows the possibility to acces the passwd system file (as long as not shadowed). Any other files that are readable by 'everybody' may be accessed. Joe Austin, MIVA's CEO offers updating any old htnlscript engine (I suppose for free). Read the original posts in the bugtraq:
top
|