[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Full-Disclosure] Confixx 2.0.xx SQL_Injections and reading MySQL Root-PW
- To: <full-disclosure@xxxxxxxxxxxxxxxx>
- Subject: Re: [Full-Disclosure] Confixx 2.0.xx SQL_Injections and reading MySQL Root-PW
- From: "Tim" <tim@xxxxxxxxxx>
- Date: Tue, 9 Mar 2004 16:27:48 +0100
>
> Confixx Perl Debugger
>
> using:
>
> ; /bin/cat location_of_Confixx_config_file
>
>
> to read the config with MySQL Root-PW
This only works if safe_mode is disabled in php.ini
I could verify this using safe_mode = off, but enabling it gives me
an error that cgi-bin/test.pl; does not exist. So this is a bug, but
running confixx with safe_mode off is not recommended and should
not be done, as there are other ways to read the file besides the confixx
scripts.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html