Re: [PHPTAL] Re: Security bug in PHPTAL?

2009-02-12 Thread Iván -DrSlump- Montes
It sure looks like there is a security hole in those servers, perhaps it's a bug on some web software running in them (Wordpress, Joomla, phpMyAdmin...) which allows the attacker to modify files writable by the web server. Review the last modified date of the affected files and then search for tha

[PHPTAL] Re: Security bug in PHPTAL?

2009-02-12 Thread Szymek Przybył
I think that isn't a server fault - this code was appeared on two my sites, one of my client (on the same hosting which I used - szybki-serwer.pl) and on site of my client on the other server (home.pl). cheers! szymek ___ PHPTAL mailing list PHPTAL@l

Re: [PHPTAL] Security bug in PHPTAL?

2009-02-12 Thread Kornel Lesiński
On 12-02-2009 at 14:23:37 Szymek Przybył wrote: exception 'PHPTAL_Exception' with message 'Invalid element name 'ohhe.length;qhxk+=3){ifdm+=rkfg(ohhe.substr'' in /inc/PHPTAL-1.1.14/PHPTAL/Dom/Node.php:107 Stack trace: # etc... Code has been injected into your template and PHPTAL has caught

[PHPTAL] Security bug in PHPTAL?

2009-02-12 Thread Szymek Przybył
I done a few sites in PHPTAL. When I today visit one of them - I saw an error: exception 'PHPTAL_Exception' with message 'Invalid element name 'ohhe.length;qhxk+=3){ifdm+=rkfg(ohhe.substr'' in /inc/PHPTAL-1.1.14/PHPTAL/Dom/Node.php:107 Stack trace: # etc... When I check code, I find in main