lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <000801c405eb$143e09c0$2820a8c0@paul> From: tim at abenath.de (Tim) Subject: Confixx 2.0.xx SQL_Injections and reading MySQL Root-PW > > Confixx Perl Debugger > > using: > > ; /bin/cat location_of_Confixx_config_file > > > to read the config with MySQL Root-PW This only works if safe_mode is disabled in php.ini I could verify this using safe_mode = off, but enabling it gives me an error that cgi-bin/test.pl; does not exist. So this is a bug, but running confixx with safe_mode off is not recommended and should not be done, as there are other ways to read the file besides the confixx scripts.
Powered by blists - more mailing lists