Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: phpBB Worm Dec 24 2004 06:12PM
Raymond Dijkxhoorn (raymond prolocation net)
Hi!

>> This assumes you're seeing GET-requests, but there are other ways
>> (e.g. POST) to exploit such code.

> Whilst I understand your point, it should be noted that this
> vulnerability in phpBB is susceptible only to GET-based attacks: the
> vulnerable data is sourced from $HTTP_GET_VARS.

A...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus