BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: @cid stats v2.3 File Include Nov 06 2006 05:30PM
Heiko Wundram (admin xencon net)
Am Sonntag, 5. November 2006 23:33 schrieb mahmood ali:
> <snip bullcrap>

Completely bogus.

If you look closely, the corresponding code in install.php3 is used to create
a config file which contains a statement setting $repertoire (from a user
input, so here is your injection attack for an insta...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus