1 By Michael Brooks
2 Vulnerability type: Multiple Remote System commands execution.
3 Software: Anon Proxy Server
4 Home page:http://sourceforge.net/projects/anonproxyserver/
5 Affects version: 0.100
7 Example exploit:
10 A virtually identical flaw exists in diagconnect.php however it takes longer to execute.
12 Anon Proxy Server forces magic_quotes_gpc=on, However magic_quotes_gpc does not protect the system() function from
taint. For protection you should use the escapeshellarg() function. Removing diagdns.php and diagconnect.php is the
best temporary solution. Also magic_quotes_gpc is being removed in php6, so Anon Proxy Server will have to revamp t
16 # milw0rm.com [2007−12−14]
Anon Proxy Server 0.1000 Remote Command Execution Vulnerability