Virgil CGI Scanner by Mark Ruef has a vulnerability where user input is trusted without being sanitized and is actually populating bash variables which end up getting executed. Simple exploit examples are included.
db03d67f3f01a9badd1d398868b94862
© 2012 Packet Storm. All rights reserved.