[pmwiki-users] Online test available for latest security vulnerability

Patrick R. Michaud pmichaud at pobox.com
Tue Sep 5 20:22:46 CDT 2006


On Tue, Sep 05, 2006 at 07:42:57PM -0400, Pico wrote:
> Patrick R. Michaud wrote:
> >Today I've quickly put together a system that allows wiki
> >administrators to easily test if their site is vulnerable to
> >the register_globals problem described earlier.  
> >
> >The starting page is at http://www.pmwiki.org/wiki/PmWiki/Analyzer .
> >There are instructions on the page, but I'll give an overview of
> >the process here.
> [snip]
> 
> I get various errors in the header:
> 
> Warning: fopen(): php_network_getaddresses: getaddrinfo failed: Name or 
> service not known in /home/pmichaud/pmwiki/local/PmWiki.Analyzer.php on 
> line 69

The url you enter probably needs to have a trailing slash -- i.e.,

    http://pico.ben-amotz.com/

instead of

    http://pico.ben-amotz.com

I'll see about having the script detect and fix this particular situation.

Pm




More information about the pmwiki-users mailing list