Redditãçºãã¦ããã¾ããã以ä¸ã®è¨äºãç®ã«æ¢ã¾ãã¾ããã New Class of Vulnerability in Perl Web Applications ãã£ããã¨ããã¨ä»¥ä¸ã®æ§ãªå 容ã§ã CGI.pmã®paramã¡ã½ããã®è¿ãå¤ãããã·ã¥ã«çªã£è¾¼ãã§ããç®æããã ã¯ã¨ãªæååã«ååã®ãã©ã¡ã¼ã¿ãè¤æ°ã»ããããã¨ãé åå¤ãè¿ã é åãããã·ã¥ã«çªã£è¾¼ããã¨ã«ãããå¥ã®ãã¼ã®å¤ãå¤æ´ããã ç§ã¯ãã®å 容ã«èå³ãæã¡ã¾ããã®ã§ã以ä¸ã«è©³ãã説æãã¾ãã PoC å ã¨ã³ããªã«ãPoCãåºã¦ããã¾ãããå°ãæãããããã®ã以ä¸ã«ç¤ºãã¾ãã #!/usr/bin/perl use strict; use CGI; my $cgi = new CGI; my $loginname = 'smith'; my $password = 'a3k!sz9'; my %user = ('log
{{#tags}}- {{label}}
{{/tags}}