Re: (php?) bug exploit report

2004-01-20 Thread Giannis Vrentzos
Chris Morris wrote: At 10:00 on Tue, 20 Jan 2004, Oliver Hitz wrote: On 19 Jan 2004, Csan wrote: The URL is part of a postnuke site and they could start up the telnetd binary with invoking an URL similar to the above URL! Is this a known sechole? I think you should be able to avoid such ex

Re: (php?) bug exploit report

2004-01-20 Thread Giannis Vrentzos
Chris Morris wrote: At 10:00 on Tue, 20 Jan 2004, Oliver Hitz wrote: On 19 Jan 2004, Csan wrote: The URL is part of a postnuke site and they could start up the telnetd binary with invoking an URL similar to the above URL! Is this a known sechole? I think you should be able to avoid such exploits