
Full Disclosure mailing list archives
Re: ashnews Cross-Site Scripting Vulnerability
From: "George A. Theall" <theall () tifaware com>
Date: Mon, 30 Jan 2006 21:47:40 -0500
On Tue, Jan 31, 2006 at 12:50:05AM +0000, Dan B UK wrote:
Did you even look at the source code for this script. If you had then you would see that in the case of register_global's being turned on there is a bigger issue to worry about; Remote/Local File Inclusion - Server side.
Is this different from what Phil Dunn reported 2.5 years ago? http://www.securityfocus.com/archive/1/329910 George -- theall () tifaware com
Attachment:
_bin
Description:
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- ashnews Cross-Site Scripting Vulnerability zeus olimpusklan (Jan 30)
- Re: ashnews Cross-Site Scripting Vulnerability Dan B UK (Jan 30)
- Re: ashnews Cross-Site Scripting Vulnerability George A. Theall (Jan 30)
- Re: ashnews Cross-Site Scripting Vulnerability DanB-FD (Jan 31)
- Re: ashnews Cross-Site Scripting Vulnerability DanB-FD (Jan 31)
- Re: ashnews Cross-Site Scripting Vulnerability George A. Theall (Jan 30)
- Re: ashnews Cross-Site Scripting Vulnerability Dan B UK (Jan 30)