Researcher: nuffsaid Ref: http://www.milw0rm.com/exploits/3079 (currently down; come back, str0ke!). alternate is http://securityreason.com/exploitalert/1698 The very top of the code is: error_reporting(E_ALL); include $current_path . 'inc/session.inc.php'; etc., as specified in the original report. - Steve