BugTraq
Re: phpBB 2.0.18 SQL Query problem Nov 15 2005 10:52PM
max jestsuper pl
>This isn't a security problem. Why post it to Bugtraq?
No? Are you sure? For example can you see path.
Good script have limits for inputs like vb.

phpbb don't have.

result:
Fatal error: Allowed memory size of 8388608 bytes exhausted (tried to allocate 1746401 byt
es) in /www/2018/phpBB2/includes/functions_search.php on line 27

it is path disclosure

or can you see sql errors

good php script isn't dependant of php env.

> Did you reported this to the PhpBB bugtracker?

yes. no response.

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus