mailing list archives
Re: ashnews Cross-Site Scripting Vulnerability
From: "George A. Theall" <theall () tifaware com>
Date: Mon, 30 Jan 2006 21:47:40 -0500
On Tue, Jan 31, 2006 at 12:50:05AM +0000, Dan B UK wrote:
Did you even look at the source code for this script. If you had then
you would see that in the case of register_global's being turned on
there is a bigger issue to worry about; Remote/Local File Inclusion -
Is this different from what Phil Dunn reported 2.5 years ago?
theall () tifaware com
Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia - http://secunia.com/