Full Disclosure mailing list archives
Re: Advisory 18/2005: PHP Cross Site Scripting (XSS) Vulnerability in phpinfo()
From: Stefan Esser <sesser () php net>
Date: Mon, 31 Oct 2005 19:15:31 +0100
Hello Matthew,
That's a hell of a turnaround for you, Esser. It's the first security bug I've reported in your software that's actually been fixed. And it only took you *THREE YEARS*. We're finally making some progress here.
Mr. Murphy, I don't know what your problem is, but the bug you refer to and that is described in the bug tracker post is not the bug the advisory contains. Just because you reported some XSS vulnerability in phpinfo() does not mean that you can claim credit for every phpinfo() XSS vulnerability that exists. So please simply shut up and go cry elsewhere.
Next time, you could try giving me credit for my research as well. Thanks.
Yeah well... If you report the bug first you can get credit. Stefan Esser -- -------------------------------------------------------------------------- Stefan Esser sesser () php net Hardened-PHP Project http://www.hardened-php.net/ GPG-Key gpg --keyserver pgp.mit.edu --recv-key 0x15ABDA78 Key fingerprint 7806 58C8 CFA8 CE4A 1C2C 57DD 4AE1 795E 15AB DA78 -------------------------------------------------------------------------- _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Re: Advisory 18/2005: PHP Cross Site Scripting (XSS) Vulnerability in phpinfo() Stefan Esser (Nov 01)