Re: New command execution vulnerability in myPhpAdmin

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Tue, 31 Jul 2001, Mark Renouf wrote:

> I would HIGHLY
> recommend turning off  register_globals in php.ini (which is the default
> in set in php.ini-dist for php4+).

This is incorrect. Currently register_globals is by default
On, and most scripts out there assume that it is so. Whether or not
it will remain as so is still open for discussion.

Also see Rasmus Lerdorf's proposal:

	http://marc.theaimsgroup.com/?l=php-dev&m=99638397319055&w=2

-- 
<---------------------------------------------------------------------->
          Heikki Korpela -- heko@iki.fi -- http://iki.fi/heko/


[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux