Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email email@example.com
Re: [Full-Disclosure] Confixx 2.0.xx SQL_Injections and reading MySQL Root-PW
From: Tim (timabenath.de)
Date: Tue Mar 09 2004 - 09:41:53 CST
> Confixx Perl Debugger
> ; /bin/cat location_of_Confixx_config_file
> to read the config with MySQL Root-PW
okay, if you have safe_mode = on and do "cgi-bin/test.pl; cat bla" this
gives an error that cgi-bin/test.pl; does not exist.
If you do "cgi-bin/test.pl ; cat bla" the perldebugger works but will not
cat the file.
Full-Disclosure - We believe in it.