9.05 27/08/2005 Looking Glass v20040427 arbitrary commands execution / cross site scripting description: Looking Glass is a pretty extensive web based network querying tool for use on php enabled servers. site: http://de-neef.net/articles.php?id=2&page=1 download page: http://de-neef.net/download.php?file=2 a) XSS: http://[target]/[path]/footer.php?version[fullname]= http://[target]/[path]/footer.php?version[homepage]="> http://[target]/[path]/footer.php?version[no]= http://[target]/[path]/header.php?version[fullname]= http://[target]/[path]/header.php?version[no]= http://[target]/[path]/header.php?version[author]=--> http://[target]/[path]/header.php?version[email]=--> b) arbitrary command execution: a user can execute arbitrary commands using pipe char in DNS lookup query field poc exploit:
9.05 27/08/2005
Loooking Glass remote commands execution poc exploit by rgod
a script by rgod at http://rgod.altervista.org