lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 29 Jan 2007 14:11:17 +0100 (CET)
From: bzhbfzj3001@...akemail.com
To: bugtraq@...urityfocus.com
Subject: Fake: Open Conference Systems = 2.8.2 Remote File Inclusion

On Sat, 27 Jan 2007 trzindan@...mail.com wrote:

> #########################################################################
> # Open Conference Systems <= 2.8.2 Remote File Inclusion
> # Download Source : http://pkp.sfu.ca/ocs/download/ocs-1.1.3.tar.gz
> #
> # Found By        : Tr_ZiNDaN
> # Location        : TurkeY --  #trzindan@...mail.fr
> ########################################################################
> file ;
>  import_xml.php
>
Note how this package does not even contain a file called 
'import_xml.php'.

I think you are referring to this package: 
http://www.oemr.org/files/openemr-2.8.1.tar.gz

Unfortunately your advisory is once again, fake. The variable you are 
referring to is set in interface/globals.php which is of course included 
before the mentioned include statement.

You've got your fake advisories mixed up.

Note how both of these packages appear in this list, and also your other 
advisory:

http://www.milw0rm.com/sploits/milw0rm.tar.bz2

(platforms/php/remote subdirectory)


I suppose we're about to see a report that php is insecure, based on the 
number of advisories on bugtraq?

Tinus

Powered by blists - more mailing lists