Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: PHPBB 2.0.20 persistent issues with avatars May 14 2006 04:58AM
Paul Laudanski (zx castlecops com)
On 12 May 2006 rgod (at) autistici (dot) org [email concealed] wrote:

> (3) inject some php code inside jpeg files as EXIF metadata content:
> this, in combinations with third party vulnerable code can be used
> to compromise the server where PHP is installed.
> Should be enough to check for php code inside the temporary file...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus