Bug#339437: PMASA-2005-6 when "register_globals = on"

2005-11-16 Thread Piotr Roszatycki
Dnia Wednesday 16 of November 2005 13:17, Martin Schulze napisał: > > Vuln 1: > > Full Path Disclosures in the following files: > > > Vuln 2: > > Http Response Splitting in libraries/header_http.inc.php > > Do you know if this is the same vulnerability as the first one above? The Full Path Disclos

Bug#339437: PMASA-2005-6 when "register_globals = on"

2005-11-17 Thread Martin Schulze
Piotr Roszatycki wrote: > Dnia Wednesday 16 of November 2005 13:17, Martin Schulze napisa?: > > > Vuln 1: > > > Full Path Disclosures in the following files: > > > > > Vuln 2: > > > Http Response Splitting in libraries/header_http.inc.php > > > > Do you know if this is the same vulnerability as the

Bug#339437: PMASA-2005-6 when "register_globals = on"

2005-11-17 Thread Piotr Roszatycki
Dnia Thursday 17 of November 2005 10:22, Martin Schulze napisał: > > Additionaly, I've fixed the important bug #324318. Please, include the > > patch for this bug to stable release. The patch doesn't change program > > functionality and resolve more problems with bad configration file which > > are