Open Conference Systems = 2.8.2 Remote File Inclusion Jan 27 2007 12:52PM
trzindan hotmail com (3 replies)
Fake: Open Conference Systems = 2.8.2 Remote File Inclusion Jan 29 2007 01:11PM
bzhbfzj3001 sneakemail com (1 replies)
On Sat, 27 Jan 2007 trzindan (at) hotmail (dot) com [email concealed] wrote:

> ########################################################################
#
> # Open Conference Systems <= 2.8.2 Remote File Inclusion
> # Download Source : http://pkp.sfu.ca/ocs/download/ocs-1.1.3.tar.gz
> #
> # Found By : Tr_ZiNDaN
> # Location : TurkeY -- #trzindan (at) hotmail (dot) fr [email concealed]
> ########################################################################

> file ;
> import_xml.php
>
Note how this package does not even contain a file called
'import_xml.php'.

I think you are referring to this package:
http://www.oemr.org/files/openemr-2.8.1.tar.gz

Unfortunately your advisory is once again, fake. The variable you are
referring to is set in interface/globals.php which is of course included
before the mentioned include statement.

You've got your fake advisories mixed up.

Note how both of these packages appear in this list, and also your other
advisory:

http://www.milw0rm.com/sploits/milw0rm.tar.bz2

(platforms/php/remote subdirectory)

I suppose we're about to see a report that php is insecure, based on the
number of advisories on bugtraq?

Tinus

[ reply ]
Re: Fake: Open Conference Systems = 2.8.2 Remote File Inclusion Jan 29 2007 07:14PM
MichaÅ? Melewski (mike carstein kill-9 pl) (2 replies)
Re: Fake: Open Conference Systems = 2.8.2 Remote File Inclusion Jan 30 2007 05:00PM
bzhbfzj3001 sneakemail com
Re: Fake: Open Conference Systems = 2.8.2 Remote File Inclusion Jan 29 2007 09:26PM
MichaÅ? Melewski (mike carstein kill-9 pl)
Re: Open Conference Systems = 2.8.2 Remote File Inclusion Jan 28 2007 09:09PM
Stefano Zanero (s zanero securenetwork it)
Re: Open Conference Systems = 2.8.2 Remote File Inclusion Jan 27 2007 08:55PM
MichaÅ? Melewski (mike carstein kill-9 pl)


 

Privacy Statement
Copyright 2010, SecurityFocus