|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 46
Members: 0
Total: 46
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Jeruvy |
|
Replies: 9 |
Views: 22162 |
|
|
|
|
|
|
dissable the
No, this is not option.
Why?
Same thing could appears in guestbook or somethine else.
Example?
And we have to leave ability to include
Then don't mess with it. I'm ... |
|
|
|
Jeruvy |
|
Replies: 7 |
Views: 12796 |
|
|
|
|
|
|
Even if it's a local variable, it still can be used for XSS
Call me skeptical but I'd like to see a PoC.
Thanks, |
|
|
|
|
Could you post this on the coppermine forum?
I don't know the url off hand, but you can also post any bugs here:
http://www.cpgnuke.com/Forums2/viewforum/f=4.html
AFAIK, most published holes ... |
|
|
|
Jeruvy |
|
Replies: 18 |
Views: 42020 |
|
|
|
|
|
|
I wonder if this may be the reason...
if (!defined('ADMIN_PAGES')) { header('Location: ../../'); exit; }
J. |
|
|
|
Jeruvy |
|
Replies: 31 |
Views: 40215 |
|
|
|
|
|
|
You need 6+ days to crack 8 character long password md5 hash..
6 days!?!?!?? you need to read more..
With some real dictionary hashes, it should take an hour or so =)
l0phtcrack wil ... |
|
|
|
Jeruvy |
|
Replies: 4 |
Views: 17685 |
|
|
|
|
|
|
Hi waraxe,
My first post on the board, but you've certainly seen my feedback on your disclosures.
This patch breaks several websites.
The problem is the setting of
$modpath = '';
If ... |
|
|
Page 1 of 1 |
All times are GMT |
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|