Re: [geeklog-users] Geeklog/Gallery vulnerability

2003-12-09 Thread Jason Signalness
Thanks Tony. Tony Bibbs wrote: Correct, it is only with that plugin. Read this: http://www.geeklog.net/article.php?story=2003120922482655 --Tony Dirk Haun wrote: Jason, This article worries me a bit: http://www.securityfocus.com/guest/24043 [...] The vulerability discussed allowed m

Re: [geeklog-users] Geeklog/Gallery vulnerability

2003-12-09 Thread Tony Bibbs
Correct, it is only with that plugin. Read this: http://www.geeklog.net/article.php?story=2003120922482655 --Tony Dirk Haun wrote: Jason, This article worries me a bit: http://www.securityfocus.com/guest/24043 [...] The vulerability discussed allowed me to write arbitrary data to the s

Re: [geeklog-users] Geeklog/Gallery vulnerability

2003-12-09 Thread Jason Signalness
Dirk Haun wrote: Jason, This article worries me a bit: http://www.securityfocus.com/guest/24043 [...] The vulerability discussed allowed me to write arbitrary data to the server's hard disk, run all kinds of shell commands, and get the output back in my browser. Worrying to be s

Re: [geeklog-users] Geeklog/Gallery vulnerability

2003-12-09 Thread Dirk Haun
Jason, >This article worries me a bit: >http://www.securityfocus.com/guest/24043 [...] >The vulerability discussed allowed me to write arbitrary data to the >server's hard disk, run all kinds of shell commands, and get the output >back in my browser. Worrying to be sure. Hmm, I've only skimmed