Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: php 4.x php5.2.x all "show_source()" ,"highlight_file()" bypass‏ Jan 06 2009 12:36PM
Slack Traq (slacktraq yahoo com)

There is no bug so no exploit can exist. File /etc/passwd is readable by any user (inside PHP with safe_mode disabled also) as it doesn't contain very sensitive information such as user passwords.

Double check what are you posting before actually doing it please.

Regards

--- On Sun, 1/4/09, l1un...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus