[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Serious holes affecting JFFNMS

Per the following comments...

"Finally, the auth.php PHP script also includes the following code:

if (($jffnms_version=="0.0.0") && ($_SERVER["REMOTE_ADDR"]=="")) {

which could be considered a backdoor althought it does not appear to be
exploitable in a typical installation."

...it should be noted that is likely the source IP address of the 
W3.ORG validator.  So perhaps the PHP code intends to behave differently during 
a W3.ORG validation test.