Re: (SRADV00006) Remote command execution vulnerabilities in phpGroupWare

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 




In-Reply-To: <003b01c05f7c$29d6cba0$1400a8c0@homenet>

This was corrected in 0.9.10 and beyond. We now 
wipe out any attempts to set post or get vars to 
the phpgw_info array and also double check that 
none of the include values have http in them.

Seek3r
phpGroupWare Spokesperson

[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux