View Single Post
Old 07-07-2007, 06:37 AM  
bl4h
Confirmed User
 
Join Date: Jul 2006
Location: Philadelphia
Posts: 1,282
Quote:
Originally Posted by Tempest View Post
If what I think is true, that will allow someone to run any php code on your site that they want.
oh shit youre right ! http_host is the hostname the client sends to the server so it can be anything ! y those bastards !

Last edited by bl4h; 07-07-2007 at 06:39 AM..
bl4h is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote