[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <3FF1415E.5080908@ppp-design.de>
Date: Tue, 30 Dec 2003 10:11:58 +0100
From: ppp-design <security@...-design.de>
To: Golden_Eternity <bugtraq@...disoft.com>
Cc: bugtraq@...urityfocus.com, full-disclosure@...ts.netsys.com
Subject: Re: php-ping: Executing arbritary commands
Golden_Eternity wrote:
>>If ($count > $max_count && !is_numeric($count))
>
> Shouldn't that be '||' instead of '&&'?
Yes, of course. Sorry, this typo should have been fixed before releasing
the advisory.
Thanks a lot for the hint,
Jens Liebchen
ppp-design
--
ppp-design
http://www.ppp-design.de
Public-Key: http://www.ppp-design.de/pgp/ppp-design.asc
Fingerprint: 5B02 0AD7 A176 3A4F CE22 745D 0D78 7B60 B3B5 451A
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
Powered by blists - more mailing lists