From: f.riphagen(at)gmail.com To: moderators(at)osvdb.org Date: Fri, 11 Aug 2006 20:57:46 +0200 Subject: [OSVDB Mods] [Change Request] 24943: phpMyAgenda agenda.php3 rootagenda Variable Remote File Inclusion Hi, I don't know if this is interesting to report (also because the bug is > 4 months old), but there are more files that not sanitize $rootagenda in this version, these are: agendaplace.php3, agendaplace2.php3, infoevent.php3, agenda.php3, agenda2.php3 -- Ferdy From: f.riphagen(at)gmail.com To: moderators(at)osvdb.org Date: Sat, 12 Aug 2006 17:41:30 +0200 Subject: [OSVDB Mods] Re: [Change Request] 24943: phpMyAgenda agenda.php3 rootagenda Variable Remote File Inclusion Forgot to mention this it is patched in version 3.1 beta 1 -- Ferdy