[37049] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Full path disclosure and sql injection on CubeCart 2.0.1

daemon@ATHENA.MIT.EDU (sculptex@sculptex.co.uk)
Sat Oct 23 01:54:21 2004

Date: 21 Oct 2004 22:59:10 -0000
Message-ID: <20041021225910.29383.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: <sculptex@sculptex.co.uk>
To: bugtraq@securityfocus.com

In-Reply-To: <20041006144016.28823.qmail@www.securityfocus.com>

Solution

INSERT
  
if (!is_numeric($cat_id))
   unset($cat_id); 

BEFORE

include("header.inc.php");

IN

index.php


home help back first fref pref prev next nref lref last post