[VIM] Re: [badroot security] probe.cgi: Remote Command Execution

Steven M. Christey coley at linus.mitre.org
Tue Jul 12 13:58:35 EDT 2005



On Tue, 12 Jul 2005, security curmudgeon wrote:

> : Product .......  probe.cgi

I did a lot of looking for this myself yesterday.  The closest I got was
some product for grid/cluster software monitoring developed in Thailand,
but I couldn't find a usable download, gave up, and forgot to write down a
summary of what I had found.  I have no idea if I was even barking up the
right tree since I couldn't find a usable probe.cgi from that product.

Oh wait, here it is - OpenSCE SCMSWeb was the product I was *GUESSING* at.
No idea if it has a probe.cgi.

There's a probe.cgi in scmsweb-3.0.10.tar.gz from here:

  ftp://osl.cpe.ku.ac.th/pub/sce/current/src/

But probe.cgi doesn't seem to have anything related to "olddat", and in
fact a grep through all the files yields nothing.

So, it's not SCMSWeb.

- Steve


More information about the VIM mailing list