LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - News > Syndicated Linux News
User Name
Password
Syndicated Linux News This forum is for the discussion of Syndicated Linux News stories.

Notices


Reply
  Search this Thread
Old 01-09-2006, 06:01 PM   #1
LXer
LXer NewsBot
 
Registered: Dec 2005
Posts: 128,477

Rep: Reputation: 118Reputation: 118
LXer: Adodb Multiple Test Scripts Remote Command Execution ...


Published at LXer:

Two vulnerabilities were identified in ADOdb, which could be exploited by remote attackers to execute arbitrary commands. The first issue is due to an input validation error in the "server.php" test script that does not properly validate the "sql" variable, which could be exploited by attackers to execute arbitrary SQL queries (when the MySQL password for the root user is empty). The second flaw is due to an input validation error in the "tests/tmssql.php" test script that does not properly validate the "do" parameter, which could be exploited by remote attackers to call arbitrary PHP functions.

Read More...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Remote Execution issinho Linux - Networking 5 07-08-2005 01:11 PM
Parallel Execution Capable Scripts? irfanhab Programming 5 08-28-2004 06:04 AM
Execution of PERL scripts in Linux which is compiled in WINDOWs environment to_veera Linux - Software 3 06-18-2004 08:50 AM
Remote Command Execution via mobile phone Sammy2ooo Linux - Software 6 06-27-2003 03:42 AM
Command to list line length of multiple scripts Tekime Linux - General 2 09-06-2002 01:04 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - News > Syndicated Linux News

All times are GMT -5. The time now is 08:41 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration