Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
sitex multiple vulnerabilities Feb 23 2007 07:49PM
none none com
global risk:critical

upload vulnerability:
in user profile upload an avatar with a double extension like :
file.php.jpg
once it's done,you gone get an error like:Fatal error: Call to undefined function imagedestroy() in /.
but the last extension (jpg) will be removed by the script, and stored in :...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus