Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email email@example.com
Date: Sat Mar 10 2007 - 15:51:51 CST
On Sat, 10 Mar 2007 15:15:54 CST, Paul Schmehl said:
> Given the syntax of this function, wgBreakFrames can only have one of two
> values: true or false.
> I'd be interested to see some POC that would show how you would exploit
The first thing to do is abuse the variable. In addition to true and false, try
3, 0 , -37, "Cabbage", and maybe "true) and (my_evil_function()))". See if you
can force it to throw a syntax error that creates a 404 page or something that
contains *other* input you control, especially if it finds its way to an eval().
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)
Comment: Exmh version 2.5 07/13/2001
-----END PGP SIGNATURE-----
Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia - http://secunia.com/