




h4ck3rz wrote:help me!!!
I think I know both the bug and the vuln part, and I think I know how to fix the vuln. It uses the function html**e**a***a*s, right? If it's right, how to fix the bug? could I just change that superglobal array into another superglobal array? (POST to GET perhaps). I've already tried that but that didn't work either. Or maybe, the line I tried to fix is incorrect? once again, help me!

eljonto wrote:
you only need to submit one line, i.e. the bug and the vuln are on the same line. you are correct with the h**********s bit, so you know what line the bug is one. You've noticed the inconsistency of the form methods, which one do you think you have to change?

h4ck3rz wrote:eljonto wrote:
you only need to submit one line, i.e. the bug and the vuln are on the same line. you are correct with the h**********s bit, so you know what line the bug is one. You've noticed the inconsistency of the form methods, which one do you think you have to change?
I still didn't get it. I think I have to change the one in the PHP script, but to do that, I must change more than one line (have to fix the IF part too, right?). But, if I change the one in the form, I can't fix the vuln. And one more question, is the function have to followed by any other parameters?



Users browsing this forum: No registered users and 0 guests