Hacker News new | ask | show | jobs
by kkl 4089 days ago
Interesting. The D-Link security advisory (http://securityadvisories.dlink.com/security/publication.asp...) states that the issue was only partially resolved. What was changed (aside from adding an additional buffer overflow) in the patch that attempted to alleviate these issues?
1 comments

Like the article says, they make sure the command to system is one of their php files before running the system command.