|
Bugtraq
mailing list archives
Fake: Open Conference Systems = 2.8.2 Remote File Inclusion
From: bzhbfzj3001 () sneakemail com
Date: Mon, 29 Jan 2007 14:11:17 +0100 (CET)
On Sat, 27 Jan 2007 trzindan () hotmail com wrote:
#########################################################################
# Open Conference Systems <= 2.8.2 Remote File Inclusion
# Download Source : http://pkp.sfu.ca/ocs/download/ocs-1.1.3.tar.gz
#
# Found By : Tr_ZiNDaN
# Location : TurkeY -- #trzindan () hotmail fr
########################################################################
file ;
import_xml.php
Note how this package does not even contain a file called
'import_xml.php'.
I think you are referring to this package:
http://www.oemr.org/files/openemr-2.8.1.tar.gz
Unfortunately your advisory is once again, fake. The variable you are
referring to is set in interface/globals.php which is of course included
before the mentioned include statement.
You've got your fake advisories mixed up.
Note how both of these packages appear in this list, and also your other
advisory:
http://www.milw0rm.com/sploits/milw0rm.tar.bz2
(platforms/php/remote subdirectory)
I suppose we're about to see a report that php is insecure, based on the
number of advisories on bugtraq?
Tinus
By Date
By Thread
Current thread:
|