Re: PhoenixPHP exploit fix!
What exploit is this and without it what can the exploit do?
Re: PhoenixPHP exploit fix!
Quote:
Originally Posted by
wy479
What exploit is this and without it what can the exploit do?
I'm not sure what it can do, I just added $core->EscapeString before $_GET['ip'];
Re: PhoenixPHP exploit fix!
This fix prevents SQL injection......
Re: PhoenixPHP exploit fix!
Quote:
Originally Posted by
leenster
This fix prevents SQL injection......
This. :P
Re: PhoenixPHP exploit fix!
This fixes the most commonly known sql injection exploit, which can be exploited with the software "Havij".
Re: PhoenixPHP exploit fix!
Re: PhoenixPHP exploit fix!
Re: PhoenixPHP exploit fix!
Thnaks this will be added right away and your register fix
Re: PhoenixPHP exploit fix!
I tried on 2 of index nothing beacuse i got many fails on my retro home
Re: PhoenixPHP exploit fix!
Thank You so much, This is so commonly used.
http://Site/index.php?error=ban&user=%Inject_here%
Thats the fix for it!
Re: PhoenixPHP exploit fix!
Re: PhoenixPHP exploit fix!
Nice.
Lesson: Never use raw commands.
Re: PhoenixPHP exploit fix!
I added this, As soon as you go on site it says you are banned but you can sign in :S, I dont think its worth it. Anyone got a fix?