Steven M. Christey wrote: > from 2008: http://www.milw0rm.com/exploits/6040 > > These vectors for the id parameter in config.php and download.php were > also disclosed by eVuln in 2006, albeit for a different version (version > 2006.03.07, non-pro). See CVE-2006-1278 Are you counting [MIL] 6040 as a dupe from CVE-2006-1278?