Matias, may your server is configured with magic_quotes disabled, so, the " is not slashed and we have a basic sql injection. Im not sure because I have not seen the source codes to say that, but it's what looks like. Is there a addslashes in the code ? []'ss Daniel ----- Original Message ----- From: "Udo Müller" <info@xxxxxxxx> To: <bugtraq@xxxxxxxxxxxxxxxxx> Sent: Thursday, August 19, 2004 5:07 AM Subject: Re: Posible security bug in phpMyWebhosting > In-Reply-To: <200408141441.44157.matias@xxxxxxxxxxxx> > > Hi Matias, > > On Sat, 14 Aug 2004 14:41:42 -0300 you wrote: > > Hi all. > > There is a posible security bug in the phpMyWebhosting > > (http://sourceforge.net/projects/phpmywebhosting/) > > > > File: includes/functions/pmwh.php > > Function: test > > [...]>Proof of concept: try using > > > > usr: admin"-( > > pass: "asdfasdf > > I am the main developer of this piece of software and not amused that you didn't mail about this bug. > > But: I tried with actual version 0.4.0 (and also earlier version) and can't reproduce your security bug. > If I enter your information I get a "Wrong password" message. > > Could you please explain this? > > Regards Udo Müller > dev@PHPMyWebHosting >