shupp / VegaDNS

Deprecated - See VegaDNS-API

Home Page:http://vegadns.org

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

vegadns vulnerable to command injection

wireghoul opened this issue · comments

axfr_get.php does not escape the file variable, proof of concept available at: https://github.com/wireghoul/sploit-dev/blob/master/izunadrop

Thanks for reporting and the POC. This is fixed in 0.13.3.