Startpage <= 1.0 (cfgLanguage) Remote File Inclusion Vulnerability

2006-08-11 Thread sh3ll
Startpage 1.0 cfgLanguage Remote File Inclusion Author : Sh3ll Date : 2006/08/10 HomePage : http://www

Re: Startpage <= 1.0 (cfgLanguage) Remote File Inclusion Vulnerability

2006-08-14 Thread Carsten Eilers
[EMAIL PROTECTED] schrieb am Thu, 10 Aug 2006 20:53:46 +: >Sanitize Variabel $cfgLanguage in edit.php , functions.php , new.php , >PageBottom.php > >& PageTop.php Take a look at config.php: $cfgLanguage= 'uk'; // Which language do you prefer :

Re: Startpage <= 1.0 (cfgLanguage) Remote File Inclusion Vulnerability

2006-08-14 Thread noname
HE ... Security FOCUS Moderators please don't add ! cfgLanguage is defined in config.php : $cfgLanguage= 'uk'; how can you change $cfgLanguage when it is defined ? Another Fake BUG Like Mafia Moblog Vulnerability : MAFIA MoBlog BID : 19458 MAFIA : http://securityfocus.com/bid/19458

Re: Startpage <= 1.0 (cfgLanguage) Remote File Inclusion Vulnerability

2006-08-21 Thread securityfocus
I made this script a long time ago and actually I donĀ“t use it anymore (I use a newer version which is not ready for "the real world" yet). By accident I discovered this page when I showed someone how many hits you will get when you google on your own name. You say "Venedor Contacted, But No R