Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: Anyone have some basic security tips for PHP-programmers? Nov 19 2003 02:58AM
James Mitchell (reductor askmiky com)
Hello,

You have just posted a very easy to spot, very easy to exploit security
hole.

Here are just a few ways to exploit it.

Your first code block:
1. Request Variables, containing variables will be evaluated. (e.g.
$config[mysql_pass])
2. The keys will not be escaped
(file.php?a%3D1%3B+print+fil...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus