Friday, 4 May 2012
NMAP Script - NSE for detecting vulnerable PHP-CGI setups (CVE2012-1823)
Here is my script for detecting vulnerable PHP-CGI setups (CVE2012-1823). This is a pretty scary vuln as it affects a lot of installations. Here is the full advisory: http://eindbazen.net/2012/05/php-cgi-advisory-cve-2012-1823/ I'm going to look more into it to write a reliable exploitation script too. So far it seems the -r flag is not available in all the setups and we will need to exploit via
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment