Jump to content

Recommended Posts

  • Replies 114
  • Created
  • Last Reply

Top Posters In This Topic

most likely what i amsaying is whoever coded the script used superglobals to code it with which isnt safe at all. i'd go bitch at them to secure it. and that was the wrong report but you can still run the code on that link i gave you and see for yourself. ;)

For insert.php i get this report http://pixybox.seclab.tuwien.ac.at/pixy/results.php?id=pixy_1220129868F9nqQM

 

no vulnerabilities

 

I'm confused as to what you are talking about...please point out where in insert.php I use a superglobal.

Haha, yeah.

 

So, two questions.

 

1) If a turn off superglobals will the script still run properly, or will I have to edit it?

2) If I leave the code how it is, will it be fine, because no one else will be able to access the admin.php besides me?

 

NOTE ** no, i haven't disallowed the page yet, i was going to use .htaccess but I'm having a little trouble figuring it out.

nice you  made your own 404 redirect ;D

 

 

according to zend:

 

mysql_tablename and mysql_list_tables

This function deprecated. It is preferable to use mysql_query() to issue a SQL SHOW TABLES [FROM db_name] [liKE 'pattern'] statement instead.


×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.