lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <8f6a58a30603282122k62bb8ba5g1f1c1cd08a270b3e@mail.gmail.com> Date: Wed Mar 29 06:22:21 2006 From: slythers at gmail.com (Slythers Bro) Subject: Critical PHP bug - act ASAP if you are running web with sensitive data <?php $host = "127.0.0.1"; $user = "sqluser"; $pass = "sqlpass"; ..... $foobar=html_entity_decode($_GET['foo']); echo $foobar; ?> -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20060329/6ebe6c59/attachment.html