Skip to content

fix: vuln check in http-phpmyadmin-dir-traversal - #1359

Closed
phra wants to merge 1 commit into
nmap:masterfrom
phra:patch-1
Closed

fix: vuln check in http-phpmyadmin-dir-traversal#1359
phra wants to merge 1 commit into
nmap:masterfrom
phra:patch-1

Conversation

@phra

@phra phra commented Oct 17, 2018

Copy link
Copy Markdown

it adds an additional check against a baseline response.

fixes #1358

it adds an additional check against a baseline response.

fixes nmap#1358
@dmiller-nmap

Copy link
Copy Markdown

The failing check here is my fault; the build was broken in the commit you branched from. I'm looking at your changes now.

@nmap-bot nmap-bot closed this in 93edeef Oct 17, 2018
@phra

phra commented Oct 18, 2018

Copy link
Copy Markdown
Author

hi @dmiller-nmap,
the PR was closed by @nmap-bot, should i resend it?

@dmiller-nmap

Copy link
Copy Markdown

@phra No, I applied your change with slight modifications in the commit that closed this PR. If you can confirm that the change works and you no longer get a false positive, we can also close #1358 .

@phra

phra commented Oct 19, 2018

Copy link
Copy Markdown
Author

@dmiller-nmap nmap is released under GPL2 LICENSE AFAIK. the ownership (mention of the author) of the commits should remain of the original authors. please review the way you integrate community contributions respecting your own LICENSE and the open source community efforts.

@dmiller-nmap

Copy link
Copy Markdown

@phra Thanks for your concern. For the moment, our process is documented in CONTRIBUTING.md, and is consistent with how Nmap development has been done for decades: commits made by authorized committers with appropriate credit given to original code authors in the CHANGELOG file. I will bring this issue up to @fyodor as well.

3 similar comments
@dmiller-nmap

Copy link
Copy Markdown

@phra Thanks for your concern. For the moment, our process is documented in CONTRIBUTING.md, and is consistent with how Nmap development has been done for decades: commits made by authorized committers with appropriate credit given to original code authors in the CHANGELOG file. I will bring this issue up to @fyodor as well.

@dmiller-nmap

Copy link
Copy Markdown

@phra Thanks for your concern. For the moment, our process is documented in CONTRIBUTING.md, and is consistent with how Nmap development has been done for decades: commits made by authorized committers with appropriate credit given to original code authors in the CHANGELOG file. I will bring this issue up to @fyodor as well.

@dmiller-nmap

Copy link
Copy Markdown

@phra Thanks for your concern. For the moment, our process is documented in CONTRIBUTING.md, and is consistent with how Nmap development has been done for decades: commits made by authorized committers with appropriate credit given to original code authors in the CHANGELOG file. I will bring this issue up to @fyodor as well.

@dmiller-nmap

Copy link
Copy Markdown

wow, Github was having problems last night and apparently queued this comment every time I tried to comment it, but told me nothing was happening. Sorry about that!

@phra

phra commented Oct 22, 2018

Copy link
Copy Markdown
Author

ahah, no problem :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

http-phpmyadmin-dir-traversal reports false positives

2 participants