Re: Insecure XML-RPC handling in Zope reveals the distribution physic al location.

2002-10-07 Thread BlueRaven
Cancel: the stack trace includes the full path infos. Verified on a 2.5.1 (stable) installation. -- BlueRaven There are only 10 types of people in this world... those who understand binary, and those who don't.

Re: phptonuke allows Remote File Retrieving

2002-10-17 Thread BlueRaven
PHP feature: by default, it is possible to open any world readable file. You can override this by using openbase_dir setting in php.ini and restricting file operations to a specified subset of paths. -- BlueRaven There are only 10 types of people in this world... those who understand binary