|
Open Conference Systems = 2.8.2 Remote File Inclusion Jan 27 2007 12:52PM trzindan hotmail com (3 replies) Re: Open Conference Systems = 2.8.2 Remote File Inclusion Jan 28 2007 09:09PM Stefano Zanero (s zanero securenetwork it) Re: Open Conference Systems = 2.8.2 Remote File Inclusion Jan 27 2007 08:55PM MichaÅ? Melewski (mike carstein kill-9 pl) |
|
Privacy Statement |
> ########################################################################
#
> # Open Conference Systems <= 2.8.2 Remote File Inclusion
> # Download Source : http://pkp.sfu.ca/ocs/download/ocs-1.1.3.tar.gz
> #
> # Found By : Tr_ZiNDaN
> # Location : TurkeY -- #trzindan (at) hotmail (dot) fr [email concealed]
> ########################################################################
> file ;
> import_xml.php
>
Note how this package does not even contain a file called
'import_xml.php'.
I think you are referring to this package:
http://www.oemr.org/files/openemr-2.8.1.tar.gz
Unfortunately your advisory is once again, fake. The variable you are
referring to is set in interface/globals.php which is of course included
before the mentioned include statement.
You've got your fake advisories mixed up.
Note how both of these packages appear in this list, and also your other
advisory:
http://www.milw0rm.com/sploits/milw0rm.tar.bz2
(platforms/php/remote subdirectory)
I suppose we're about to see a report that php is insecure, based on the
number of advisories on bugtraq?
Tinus
[ reply ]