Full Disclosure mailing list archives
Re: Confixx 2.0.xx SQL_Injections and reading MySQL Root-PW
From: "Tim" <tim () abenath de>
Date: Tue, 9 Mar 2004 16:27:48 +0100
Confixx Perl Debugger using: ; /bin/cat location_of_Confixx_config_file to read the config with MySQL Root-PW
This only works if safe_mode is disabled in php.ini I could verify this using safe_mode = off, but enabling it gives me an error that cgi-bin/test.pl; does not exist. So this is a bug, but running confixx with safe_mode off is not recommended and should not be done, as there are other ways to read the file besides the confixx scripts. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Confixx 2.0.xx SQL_Injections and reading MySQL Root-PW checker (Mar 09)
- Re: Confixx 2.0.xx SQL_Injections and reading MySQL Root-PW Tim (Mar 09)
- Re: Confixx 2.0.xx SQL_Injections and reading MySQL Root-PW Tim (Mar 09)
- <Possible follow-ups>
- Re: Re: Confixx 2.0.xx SQL_Injections and reading MySQL Root-PW checker (Mar 10)