TUCoPS :: Web :: Apps :: hypseek2.htm

Hyperseek ../ and %00 vulnerabilities



    Hyperseek 2000 Search Engine


    MC GaN (NerF security  gr0up advisory) found following.   Standard
    perl problem is in statistic  module - file: hsx.cgi, script  does
    not filter ../ and %00.   Through this bug, you can remotely  read
    any file and  make listing of  directory. ../ -  directory up, %00
    hex symbol, that means end of line.

    Exploit url:

    Note: directory can change and amount of ../ can vary.


    Filter symbols like:

        $dat=~ s/\0//g;

