Bugtraq mailing list archives
Re: Posible security bug in phpMyWebhosting
From: "Daniel Souza" <daniel.souza () tuxtecnologia com br>
Date: Fri, 20 Aug 2004 02:01:53 -0300
Matias, may your server is configured with magic_quotes disabled, so, the " is not slashed and we have a basic sql injection. Im not sure because I have not seen the source codes to say that, but it's what looks like. Is there a addslashes in the code ? []'ss Daniel ----- Original Message ----- From: "Udo Müller" <info () cs-ol de> To: <bugtraq () securityfocus com> Sent: Thursday, August 19, 2004 5:07 AM Subject: Re: Posible security bug in phpMyWebhosting
In-Reply-To: <200408141441.44157.matias () neiff com ar> Hi Matias, On Sat, 14 Aug 2004 14:41:42 -0300 you wrote:Hi all. There is a posible security bug in the phpMyWebhosting (http://sourceforge.net/projects/phpmywebhosting/) File: includes/functions/pmwh.php Function: test [...]>Proof of concept: try using usr: admin"-( pass: "asdfasdfI am the main developer of this piece of software and not amused that you
didn't mail about this bug.
But: I tried with actual version 0.4.0 (and also earlier version) and
can't reproduce your security bug.
If I enter your information I get a "Wrong password" message. Could you please explain this? Regards Udo Müller dev@PHPMyWebHosting
Current thread:
- Posible security bug in phpMyWebhosting Matias Neiff (Aug 14)
- <Possible follow-ups>
- Re: Posible security bug in phpMyWebhosting Müller (Aug 19)
- Re: Posible security bug in phpMyWebhosting Daniel Souza (Aug 20)
- Re: Posible security bug in phpMyWebhosting Udo Mueller (Aug 20)
- Re: Posible security bug in phpMyWebhosting Daniel Souza (Aug 20)
- Re: Fwd: Re: Posible security bug in phpMyWebhosting Matias Neiff (Aug 23)