-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi all. I test the last version that I (and everybody) can find in the web. http://sourceforge.net/projects/phpmywebhosting/ (the version 0.3.4) Please try the bug whit this version. I put this version of you panel in the page : http://www.root-solutions.com.ar/pmwh/ Cheers Matias Neiff www.root-solutions.com.ar > In-Reply-To: > <200408141441.44157.matias@xxxxxxxxxxxx> > > Hi Matias, > > On Sat, 14 Aug 2004 14:41:42 -0300 you wrote: > > Hi all. > > There is a posible security bug in the > > phpMyWebhosting > > > (http://sourceforge.net/projects/phpmywebhosting/) > > > > File: includes/functions/pmwh.php > > Function: test > > [...]>Proof of concept: try using > > > > usr: admin"-( > > pass: "asdfasdf > > I am the main developer of this piece of software > and not amused that you didn't mail about this bug. > > But: I tried with actual version 0.4.0 (and also > earlier version) and can't reproduce your security > bug. > If I enter your information I get a "Wrong password" > message. > > Could you please explain this? > > Regards Udo Müller > dev@PHPMyWebHosting -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFBJcw1CRaMUNBLpxsRAvFgAKCRiKY4HBTpEBYncRwAnJYv9O4gfwCfaBDQ zJ6erIlLOnNLXMAGjTg6nP0= =9cdS -----END PGP SIGNATURE-----