[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <000801c405eb$143e09c0$2820a8c0@paul>
From: tim at abenath.de (Tim)
Subject: Confixx 2.0.xx SQL_Injections and reading MySQL Root-PW
>
> Confixx Perl Debugger
>
> using:
>
> ; /bin/cat location_of_Confixx_config_file
>
>
> to read the config with MySQL Root-PW
This only works if safe_mode is disabled in php.ini
I could verify this using safe_mode = off, but enabling it gives me
an error that cgi-bin/test.pl; does not exist. So this is a bug, but
running confixx with safe_mode off is not recommended and should
not be done, as there are other ways to read the file besides the confixx
scripts.
Powered by blists - more mailing lists