php code injection attack
Submitted by rollins on Tue, 2009-07-07 02:28.
| Project: | phpAlbum.net |
| Version: | 0.4.1-14_fix05 |
| Component: | Code |
| Category: | bug |
| Priority: | critical |
| Assigned: | patrik |
| Status: | in work |
Description
You can execute arbitrary php commands by passing main.php specially crafted parameters. For example,
main.php?cmd=setquality&var1=1'.phpinfo().'
will result in a "create_funtion()" call that will execute the phpinfo() command.
Updates
#1 submitted by patrik on Thu, 2009-07-16 20:38
| Status: | new | » in work |
Thanx for posting! This is by far the most serious bug I ever produced ...
Dou you have more examples?

Recent comments
2 hours 12 min ago
14 hours 10 min ago
14 hours 11 min ago
14 hours 11 min ago
14 hours 11 min ago
1 day 4 hours ago
1 day 8 hours ago
1 day 22 hours ago
2 days 5 hours ago
2 days 7 hours ago