[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-Id: <1234863889.3569.2.camel@pavilion>
Date: Tue, 17 Feb 2009 10:44:49 +0100
From: Francesco Laurita <francesco@...ncesco-laurita.info>
To: Dr.linux@....net
Cc: bugtraq@...urityfocus.com
Subject: Re: RFI Bug
On Mon, 2009-02-16 at 17:13 +0000, Dr.linux@....net wrote:
> ViArt Shop 3.6 Remote File Include BUG
> include_once($root_folder_path."includes/common.php");
>
> include_once($root_folder_path . "includes/record.php");
Bogus,
$root_folder_path is defined into admin_config.php which is included one
line befere:
include_once("./admin_config.php");
include_once($root_folder_path."includes/common.php");
include_once($root_folder_path . "includes/record.php");
Regards,
--
F
Powered by blists - more mailing lists