發信站NCTU CSIE FreeBSD Server (Wed Mar 14 09:01:32 2007)
轉信站ptt!FreeBSD.csie.NCTU!not-for-mail
The first one is not a vulnerability at all - $cmd is always initialised as a constant within the script.
The second one is not a vulnerability either, as that file (filter.php) does not even exist!