FormHandler.cgi uses hard coded physical path names for templates so it is possible to read any file on the system.
982f352a5e509b2e9e1fc85b0d6714be542e0e546c96f5882dc578ee003c3f13
From: Mnemonix <mnemonix@GLOBALNET.CO.UK>
Subject: FormHandler.cgi
FormHandler.cgi available from https://www.cgi-perl.com/programs/FormHandler
uses hard coded physical paths for templates etc so it's possible to get sensitive files like /etc/passwd by modifying a site's f
orm and submitting it.
Cheers,
David Litchfield
https://www.infowar.co.uk/mnemonix/
Cerberus Information Security
+44(0)181 661 7405