[Full-disclosure] 0DAY RFI in phpBB <= 2.0.22 HOT

Slythers Bro slythers at gmail.com
Fri Jun 1 19:38:56 BST 2007


i saw that in functions_post.php :

if (!defined <http://www.phpbb.de/doku/xref/_functions/defined.html>('IN_PHPBB
<http://www.phpbb.de/doku/xref/_constants/IN_PHPBB.html>'))
  {
       die('Hacking attempt');
  }


so this RFI can't work
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20070601/e2410b2a/attachment.html 


Full-Disclosure is hosted and sponsored by Secunia.