bo-blog的一个漏洞(应该是吧)

Sep 26th, 2006
[b]P_e_r_l :php的运行库, 版本越高越好。[/b]



大家可以自己测试以下 将代码中的 “_” 去掉,建立新日志 然后提交,就会发生网页权限错误。  我觉得这个应该是个漏洞把。

Share and Enjoy:
  • Print
  • Digg
  • Sphinn
  • del.icio.us
  • Facebook
  • Mixx
  • Google Bookmarks
  • email
  • Fleck
  • Gwar
  • Haohao
  • Identi.ca
  • laaik.it
  • LinkaGoGo
  • LinkedIn
  • Linkter
  • Live
  • MisterWong
  • MisterWong.DE
  • MSN Reporter
  • MySpace
  • PDF
  • Ping.fm
  • RSS
  • Slashdot
  • Socialogs
  • Technorati
  • Tumblr
  • Twitter
  • Twitthis
  • Webride
  • Yahoo! Bookmarks
  • Yigg
  1. UNAMES
    Oct 22nd, 2006 at 13:02
    Reply | Quote | #1

    真的?那我直接在这里试试看?
    [b]Perl:php的运行库, 版本越高越好。[/b]

Note: Commenter is allowed to use '@User+blank' to automatically notify your reply to other commenter. e.g, if ABC is one of commenter of this post, then write '@ABC '(exclude ') will automatically send your comment to ABC. Using '@all ' to notify all previous commenters. Be sure that the value of User should exactly match with commenter's name (case sensitive).