lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Sat, 19 Aug 2006 00:51:50 +0200 From: "Carsten Eilers" <ceilers-lists@....de> To: <crackers_child@...ersavascilar.com>, <bugtraq@...urityfocus.com> Subject: Re: anjel Mambo Component Remote File Include Hi, crackers_child@...ersavascilar.com schrieb am Thu, 17 Aug 2006 21:09:36 +0000: >Bug İn anjel.index.php > > > include_once( '../../globals.php' ); > > require_once( '../../configuration.php' ); > > require_once( $mosConfig_absolute_path . '/includes/joomla.php' ); $mosConfig_absolute_path is set in configuration.php, there is no way to manipulate it between the two line, so there is no vulnerability. Please take a look at <http://www.securityfocus.com/archive/1/443225/30/0/threaded> Regards Carsten -- Dipl.-Inform. Carsten Eilers IT-Sicherheit und Datenschutz <http://www.ceilers-it.de>
Powered by blists - more mailing lists