[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <4548BD45.8050306@securenetwork.it>
Date: Wed, 01 Nov 2006 16:29:09 +0100
From: Stefano Zanero <s.zanero@...urenetwork.it>
To: mahmood ali <mah_k_2000@...mail.com>, bugtraq@...urityfocus.com
Subject: Re: PLS-Bannieres 1.21 (bannieres.php) File Include
mahmood ali wrote:
> PLS-Bannieres 1.21 (bannieres.php) File Include
> modules/bannieres/bannieres.php
> In Line 13 :_
>
> include "$chemin/includes/connexion.php" ;
Including ONE (1) more line of code:
$chemin = "." ;
include "$chemin$chemin/includes/connexion.php" ;
...
Another example of untested BOGUS vuln advisory...
Stefano
Powered by blists - more mailing lists