Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Unauthorized reading files on phpSysInfo Apr 25 2003 06:31PM
Wolter Kamphuis (security wkamphuis student utwente nl)
Hi,

In bug report #670222 I described the same problem and how to use it to
DoS the host. Calling "index.php?lng=../../index" creates a run-a-way
recursive loop, creating a huge load and finally crashing the
apache process. This can easily be used to DoS a webserver.
http://sourceforge.net/tracke...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus