Icy Phoenix

     
 


Post new topic  This topic is locked: you cannot edit posts or make replies. 
Page 1 of 1
 
 
Reply with quote Download Post 
Post 058-015 - Admin Hacks List SQL Injection 
 
Hi All,
the admin hacks list could have a potential issue:

http://milw0rm.com/exploits/2851

I didn't try the exploit, but after looking at the code, I would fix it in this way:

OPEN adm/admin_hacks_list.php

FIND
Code: [Download] [Hide] [Select]
if (count($_POST))


BEFORE ADD
Code: [Download] [Hide] [Select]
$hack_id = intval($hack_id);


You should apply this patch as soon as possible.
 




____________
Luca
SEARCH is the quickest way to get support.
Icy Phoenix ColorizeIt - CustomIcy - HON
 
Mighty GorgonSend private messageSend e-mail to userVisit poster's website  
Back to topPage bottom
Icy Phoenix is an open source project, you can show your appreciation and support future development by donating to the project.

Support us
 
Reply with quote Download Post 
Post Re: 058-015 - Admin Hacks List SQL Injection 
 
Thanks MG, patched on my site
 




____________
? Zuker - EDDB - LPM - Sharefields
 
ZukerSend private messageVisit poster's website  
Back to topPage bottom
Reply with quote Download Post 
Post Re: 058-015 - Admin Hacks List SQL Injection 
 
Thanks MG
 



 
moreteavicarSend private message  
Back to topPage bottom
Reply with quote Download Post 
Post Re: 058-015 - Admin Hacks List SQL Injection 
 
done
 




____________
Daniele Caporrella
www.pionierilanciano.org/forum
 
SkorpionSend private messageVisit poster's website  
Back to topPage bottom
Reply with quote Download Post 
Post Re: 058-015 - Admin Hacks List SQL Injection 
 
I Have tested the bug but it don't  work on XS.

however thanks you for the patch!
 




____________
My english isn't perfect!

http://fab120.netsons.org
http://risorsegratis.webarrivo.com
 
fab120Send private messageVisit poster's website  
Back to topPage bottom
Reply with quote Download Post 
Post Re: 058-015 - Admin Hacks List SQL Injection 
 
Thanks a lot
 



 
TheSteffenSend private message  
Back to topPage bottom
Post new topic  This topic is locked: you cannot edit posts or make replies.  Page 1 of 1
 


Display posts from previous:    

HideWas this topic useful?

Link this topic
URL
BBCode
HTML




 
Permissions List
You cannot post new topics
You cannot reply to topics
You cannot edit your posts
You cannot delete your posts
You cannot vote in polls
You cannot attach files
You can download files
You cannot post calendar events


  

 

  cron