[22850] in bugtraq
Bug in PostNuke 0.62, 0.63 and 0.64 (and possibly PHPnuke)
daemon@ATHENA.MIT.EDU (Francisco J. =?ISO-8859-1?Q?Le=F3n)
Sun Oct 14 21:06:26 2001
Message-ID: <3BC8F942.8020401@iamnet.com>
Date: Sat, 13 Oct 2001 22:32:34 -0400
From: "Francisco J. =?ISO-8859-1?Q?Le=F3n?=" <fjleon@iamnet.com>
MIME-Version: 1.0
To: bugtraq@securityfocus.com
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 8bit
Yes, i saw the code in phpnuke 5.2, and it's exactly the same, so this
probably happens in phpnuke too, so i suggest people to apply the fix
described by Magnus. The only difference is that phpnuke has a "prefix"
in the code, that postnuke uses with another name
--
Francisco J. León
IV Semestre de Lic. en Computación
LUZ - Maracaibo, Venezuela
Icq:1797523 http://espectr0.com