Changeset 743


Ignore:
Timestamp:
05/04/2012 02:36:51 PM (13 months ago)
Author:
sullo
Message:

Check for straight <?php without highlighting, and use ? to let server decide what index file is in use.

File:
1 edited

Legend:

Unmodified
Added
Removed
  • trunk/databases/db_tests

    r742 r743  
    65086508"006521","0","7","/../../windows/dvr2.ini","GET","\[generic\]","","","","","Tibetsystem DVR allows arbitrary file retrieval. See http://packetstormsecurity.org/files/109547/tibetsystem-traversal.txt","","" 
    65096509"006522","18255","7","/htdocs/../../../../../../../../../../../etc/passwd","GET","root:","","","","","SAP Internet Graphics Server (IGS) directory traversal","","" 
    6510 "006523","","38","/index.php?-s","GET","\"\>\&lt\;\?php","","","","","PHP allows retrieval of the source code via the -s parameter, and may allow command execution. See http://www.kb.cert.org/vuls/id/520827","","" 
    6511 "006523","","38","/login.php?-s","GET","\"\>\&lt\;\?php","","","","","PHP allows retrieval of the source code via the -s parameter, and may allow command execution. See http://www.kb.cert.org/vuls/id/520827","","" 
     6510"006523","","38","/?-s","GET","\"\>\&lt\;\?php","<\?php","","","","PHP allows retrieval of the source code via the -s parameter, and may allow command execution. See http://www.kb.cert.org/vuls/id/520827","","" 
     6511"006523","","38","/login.php?-s","GET","\"\>\&lt\;\?php","<\?php","","","","PHP allows retrieval of the source code via the -s parameter, and may allow command execution. See http://www.kb.cert.org/vuls/id/520827","","" 
Note: See TracChangeset for help on using the changeset viewer.