[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20050318215246.16835.qmail@mail.securityfocus.com>
Date: Fri, 18 Mar 2005 22:11:29 -0000
From: "Paul S. Owen" <paul0x01@...rstreak.net>
To: <bugtraq@...urityfocus.com>
Subject: RE: [phpbb <= 2.0.13 full path disclosure & directory listing]
> [phpbb <= 2.0.13 full path disclosure & directory listing]
>
> Author: Jocanor
> Date= 18-03-2k5
This is _not_ an issue for phpBB 2.0.x. The 2.0.x line does _not_ support
Oracle, it will not function using that DB without significant modification.
Usually the oracle.php layer is not included, unfortunately it "snuck" into
the latest release. However as noted it will not work and thus this
"exploit" cannot achieve anything unless the version of phpBB installed has
been explicitly modified (using third party Mods) to function with Oracle.
psoTFX - Paul S. Owen - phpBB Group
Powered by blists - more mailing lists