On Sat, 31 Mar 2007, Aditya K Sood wrote:
http://zeroknock.metaeye.org/analysis/gspace.xhtml
Just like your previous "double trap" XSS advisory, I fail to see the
novelty or significance of this report.
You seem to discuss an ages-old issue that had been used to exploit a
countless number of web applications, and is remediated by disabling
register_globals (ain't that off by default since PHP 4.2.0?).
/mz
----------------------------------------------------------------------------
Join us on IRC: irc.freenode.net #webappsec
Have a question? Search The Web Security Mailing List Archives:
http://www.webappsec.org/lists/websecurity/
Subscribe via RSS:
http://www.webappsec.org/rss/websecurity.rss [RSS Feed]