Just to explain for others aswel.
Pennywise.cgi is/was never voulnerable as a script itself. It's a script from Pennywise that is used for tracking logins etc etc. Problem with this script was that there were some exploiters that injected the code inside it, which made it voulnerable, and then they posted that as shells on boards. Many "great" exploiters, great as they are, didn't understand this, and started scanning for pennywise.cgi because they actually thought it was bugd. Same with phpinfo, whereami.cgi....
|