|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 78
Members: 0
Total: 78
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Koople |
|
Replies: 1 |
Views: 11880 |
|
|
|
|
|
|
I used web vulnerabilty scanner and it found a 'PHP unspecified remote arbitrary file upload vulnerability' in the vesion of PHP the site I scanned was running.
It directed me to this page: http:// ... |
|
|
|
Koople |
|
Replies: 6 |
Views: 16171 |
|
|
|
|
|
|
Not sure quite what you mean.
If you're asking if it's possible to access someone else's account, then yes. |
|
|
|
|
So is there any way to use SQL injection when a site adds slashes where it finds particular characters (" ' / ect.) in any user-input before it processes it? |
|
|
|
|
Jelsoft have been pretty clever this time.
Something that's annoying me right now is that the admin of the form has to add a site to a 'whitelist' before vBulletin will accept post requests from it ... |
|
|
Page 1 of 1 |
All times are GMT |
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|