Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Gstebuch Version 1.5 Remote Command Execution Vulnerability

From: Carsten Eilers <ceilers-lists(at)gmx.de>
Date: Fri Aug 10 2007 - 16:10:26 EDT


ilkerkandemir@mynet.com schrieb am Fri, 10 Aug 2007 09:57:48 +0000:

>echo "<meta http-equiv='refresh' content='0;URL=install.php'>";
>
>redirecting brotha ;)
>
>Not RFI

Nice try, but you should read the lines above the redirection, too:

| ";
|	exit;
| }

Your redirection is in line 6, the RFI in line 3. First hit wins: RFI. ;-)

Regards,
  Carsten Received on Fri Aug 10 16:48:18 2007

This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:11:26 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library