=========================================================== .___ __ __ _________________ __ __ __| _/|__|/ |_ / ___\_` __ \__ \ | | \/ __ | | \\_ __\ / /_/ > | \// __ \| | / /_/ | | || | \___ /|__| (____ /____/\____ | |__||__| /_____/ \/ \/ grep rough audit - static analysis tool v2.8 written by @Wireghoul =================================[justanotherhacker.com]=== php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-237- FROM {$this->db_prefix}properties php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php:238: WHERE path = '$path'"; php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php:239: $res = mysql_query($query); php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-240- while ($row = mysql_fetch_assoc($res)) { ############################################## php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-308- // lets see it it does have mime support php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php:309: $fp = popen("file -i '$fspath' 2>/dev/null", "r"); php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-310- $reply = fgets($fp); ############################################## php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-559- WHERE path LIKE '".$this->_slashify($options["path"])."%'"; php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php:560: mysql_query($query); php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-561- System::rm(array("-rf", $path)); ############################################## php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-565- $query = "DELETE FROM {$this->db_prefix}properties php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php:566: WHERE path = '$options[path]'"; php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php:567: mysql_query($query); php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-568- ############################################## php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-668- WHERE path LIKE '".$this->_slashify($options["path"])."%'"; php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php:669: mysql_query($query); php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-670- } ############################################## php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-673- SET path = '".$destpath."' php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php:674: WHERE path = '".$options["path"]."'"; php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php:675: mysql_query($query); php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-676- } else { ############################################## php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-717- FROM {$this->db_prefix}properties php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php:718: WHERE path = '".$options['path']."'"; php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-719- } ############################################## php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-750- $query = "DELETE FROM {$this->db_prefix}properties php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php:751: WHERE path = '$options[path]' php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-752- AND name = '$prop[name]' ############################################## php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-754- } php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php:755: mysql_query($query); php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-756- } ############################################## php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-782- if (isset($options["update"])) { // Lock Update php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php:783: $where = "WHERE path = '$options[path]' AND token = '$options[update]'"; php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-784- php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-785- $query = "SELECT owner, exclusivelock FROM {$this->db_prefix}locks $where"; php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php:786: $res = mysql_query($query); php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-787- $row = mysql_fetch_assoc($res); ############################################## php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-794- $where"; php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php:795: mysql_query($query); php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-796- ############################################## php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-815- ; php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php:816: mysql_query($query); php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-817- ############################################## php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-829- $query = "DELETE FROM {$this->db_prefix}locks php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php:830: WHERE path = '$options[path]' php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-831- AND token = '$options[token]'"; php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php:832: mysql_query($query); php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-833- ############################################## php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-848- FROM {$this->db_prefix}locks php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php:849: WHERE path = '$path' php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-850- "; php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php:851: $res = mysql_query($query); php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server/Filesystem.php-852- ############################################## php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server.php-980- } php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server.php:981: fpassthru($options['stream']); php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server.php-982- } ############################################## php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server.php-985- fseek($options['stream'], -$range['last'], SEEK_END); php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server.php:986: fpassthru($options['stream']); php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server.php-987- } ############################################## php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server.php-1017- } php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server.php:1018: fpassthru($options['stream']); php-http-webdav-server-1.0.0RC8/HTTP_WebDAV_Server-1.0.0RC8/HTTP/WebDAV/Server.php-1019- return; // no more headers