Archive for May, 2007
Friday 4 May 2007 @ 4:33 am
The Diesel Job Site php script at www.dieselscripts.com attracted my friend. It costs less than $50, had an attractive interface- but suffered a major vulnerability. When an hapless user installs this software on their
webserver, all data is emailed back to the vendors of this software. How’s that for privacy violations?? This information is sent from install.php, which includes the database host, database name, username, and password used to connect. Sucks big time huh? These people are shamefaced internet scalawags for such breach!
The offiending piece of crap can be found here: http://www.dieselscripts.com/diesel-job-site.html







