TUCoPS :: Web :: Apps :: pals.htm

PALS Library System "pine pipe bug" yields arbitrary files, command execution

    PALS Library System


    'UkR-XblP' found following.  This  script is derived from an  idea
    originated at St.Olaf  College to provide  a www interface  to the
    PALS Library  System.   This idea  was then  worked on  at Georgia
    State University.  This version of WebPals has been written  using
    their original ideal.

    Through this  bug you  can see  any files  and command  execution.
    Problem lies in "pine pipe bug".  Exploit:


    Nothing yet.

