Full Disclosure mailing list archives

Re: phpMyAdmin 3.x preg_replace RCE POC


From: Ryan Sears <rdsears () mtu edu>
Date: Sat, 09 Jul 2011 13:09:35 -0400


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Well that sounds like a personal problem to me. It's a good read, very
interesting stuff and definitely worth taking a look at.

Ryan

On 07/09/2011 09:51 AM, nix () myproxylists com wrote:
I'm flooded with requests for a POC and many doubt that these
vulnerabilities are exploitable. And since this vulnerability is
rather technically interesting I believe many could learn from it.

http://ha.xxor.se/2011/07/phpmyadmin-3x-pregreplace-rce-poc.html


Could you fix that font on your site? Very small light green font on black
background. It's horrible. I did not even bothered to read it in full due
to that.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iF4EAREIAAYFAk4Yi0cACgkQt/95fIeU+XZiIwD/biYpkCf2Z9YTOczFeNQNnCFc
Gbgny8mPc0v0gL1z17YA+waYzYvkXiIrA1fhNRDVyQz9BYvdlYbO6iL9zPAf1K7r
=gL1Q
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: