Another bug in phpNuke
From: David Page (david@melaniepage.worldonline.co.uk)Date: 07/28/01
- Previous message: Jake Luck: "solaris in.lpd patch where/when?"
- Next in thread: Spirit Of 1: "Windows ME file restoration"
- Reply: Spirit Of 1: "Windows ME file restoration"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Message-ID: <008401c116fe$0f6a3f10$0100a8c0@davids> From: "David Page" <david@melaniepage.worldonline.co.uk> To: <bugtraq@securityfocus.com> Subject: Another bug in phpNuke Date: Sat, 28 Jul 2001 01:41:31 +0100
Yes, i have found some bugs also...
You can execute artibility mysql statments in many of its different
scripts...
reviews.php for example..
The parmenter with the id (reviews.php?id=blah) *think* doesn't check... so
you can simply do reviews.php?id=12345 or ........ blah blah blah
I don't think its possible to execute multiple sql statments in
mysql_query(.....)
php4 will also (addslashes) automatically to ' and ". I don't think php3
does...
I contacted phpNuke 8 days ago.
- Previous message: Jake Luck: "solaris in.lpd patch where/when?"
- Next in thread: Spirit Of 1: "Windows ME file restoration"
- Reply: Spirit Of 1: "Windows ME file restoration"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|