Re: RE: (SRADV00001) Arbitrary file disclosure through PHP file upload
| From: | Stig Venaas | Date: | Tue, 05 Sep 2000 11:38:33 +0000 |
| Subject: | Re: RE: (SRADV00001) Arbitrary file disclosure through PHP file upload | ||
| References: | 1 2 3 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32123@lists.php.net to get a copy of this message | ||
On Tue, Sep 05, 2000 at 01:35:03AM +0300, Zeev Suraski wrote:
> The correct, tested fixed file (without any side effects) is available at
>
>
> http://cvsweb.php.net/viewcvs.cgi/~checkout~/php4/main/rfc1867.c?rev=1.45&content-type=text/plain
>
> The diff against version 4.0.2 is available at:
>
>
> http://cvsweb.php.net/viewcvs.cgi/php4/main/rfc1867.c.diff?r1=1.38%3Aphp_4_0_2&tr1=1.1&r2=text&tr2=1.45&diff_format=u
You also need new php_globals.h
http://cvsweb.php.net/viewcvs.cgi/~checkout~/php4/main/php_globals.h?rev=1.54&content-type=text/plain
I'm posting this just to the php-dev list now just in case it's not 100%
correct, or you want to add something.
Stig