Full Disclosure mailing list archives
Re: phpMyAdmin 3.x preg_replace RCE POC
From: Mango <h () xxor se>
Date: Sat, 9 Jul 2011 20:27:08 +0200
Ryan, for that I thank you sincerely. 2011/7/9 Ryan Sears <rdsears () mtu edu>:
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Well that sounds like a personal problem to me. It's a good read, very interesting stuff and definitely worth taking a look at. Ryan On 07/09/2011 09:51 AM, nix () myproxylists com wrote:I'm flooded with requests for a POC and many doubt that these vulnerabilities are exploitable. And since this vulnerability is rather technically interesting I believe many could learn from it. http://ha.xxor.se/2011/07/phpmyadmin-3x-pregreplace-rce-poc.htmlCould you fix that font on your site? Very small light green font on black background. It's horrible. I did not even bothered to read it in full due to that._______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iF4EAREIAAYFAk4Yi0cACgkQt/95fIeU+XZiIwD/biYpkCf2Z9YTOczFeNQNnCFc Gbgny8mPc0v0gL1z17YA+waYzYvkXiIrA1fhNRDVyQz9BYvdlYbO6iL9zPAf1K7r =gL1Q -----END PGP SIGNATURE----- _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- phpMyAdmin 3.x preg_replace RCE POC Mango (Jul 08)
- Re: phpMyAdmin 3.x preg_replace RCE POC nix (Jul 09)
- Re: phpMyAdmin 3.x preg_replace RCE POC Ryan Sears (Jul 09)
- Re: phpMyAdmin 3.x preg_replace RCE POC Mango (Jul 09)
- Re: phpMyAdmin 3.x preg_replace RCE POC Mango (Jul 09)
- Re: phpMyAdmin 3.x preg_replace RCE POC Tweedle Doh (Jul 09)
- Message not available
- Message not available
- phpMyAdmin 3.x preg_replace RCE POC Mango (Jul 10)
- Re: phpMyAdmin 3.x preg_replace RCE POC Ryan Sears (Jul 09)
- Re: phpMyAdmin 3.x preg_replace RCE POC nix (Jul 09)