| To: | bugtraq@securityfocus.com |
|---|---|
| Subject: | Fake: Open Conference Systems = 2.8.2 Remote File Inclusion |
| From: | bzhbfzj3001@sneakemail.com |
| Date: | Mon, 29 Jan 2007 14:11:17 +0100 (CET) |
| Delivered-to: | sp-com-lists@consult.net |
| Delivered-to: | bugtraq-list@securepoint.com |
| Delivered-to: | mailing list bugtraq@securityfocus.com |
| Delivered-to: | moderator for bugtraq@securityfocus.com |
| In-reply-to: | <20070127125238.14741.qmail@securityfocus.com> |
| List-help: | <mailto:bugtraq-help@securityfocus.com> |
| List-id: | <bugtraq.list-id.securityfocus.com> |
| List-post: | <mailto:bugtraq@securityfocus.com> |
| List-subscribe: | <mailto:bugtraq-subscribe@securityfocus.com> |
| List-unsubscribe: | <mailto:bugtraq-unsubscribe@securityfocus.com> |
| Mailing-list: | contact bugtraq-help@securityfocus.com; run by ezmlm |
| References: | <20070127125238.14741.qmail@securityfocus.com> |
On Sat, 27 Jan 2007 trzindan@hotmail.com wrote: Note how this package does not even contain a file called 'import_xml.php'.######################################################################### # Open Conference Systems <= 2.8.2 Remote File Inclusion # Download Source : http://pkp.sfu.ca/ocs/download/ocs-1.1.3.tar.gz # # Found By : Tr_ZiNDaN # Location : TurkeY -- #trzindan@hotmail.fr ######################################################################## file ; import_xml.php I think you are referring to this package: http://www.oemr.org/files/openemr-2.8.1.tar.gz Unfortunately your advisory is once again, fake. The variable you are referring to is set in interface/globals.php which is of course included before the mentioned include statement. You've got your fake advisories mixed up.Note how both of these packages appear in this list, and also your other advisory: http://www.milw0rm.com/sploits/milw0rm.tar.bz2 (platforms/php/remote subdirectory)I suppose we're about to see a report that php is insecure, based on the number of advisories on bugtraq? Tinus |
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Dexia website security alert, Thierry Zoller |
|---|---|
| Next by Date: | Re: local Calendar System v1.1 (lcStdLib.inc) Remote File Include, Stefano Zanero |
| Previous by Thread: | Re: Open Conference Systems = 2.8.2 Remote File Inclusion, Michał Melewski |
| Next by Thread: | Re: Fake: Open Conference Systems = 2.8.2 Remote File Inclusion, Michał Melewski |
| Indexes: | [Date] [Thread] [Top] [All Lists] |