Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Thu, 01 Jan 1970 00:00:00 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-32144@lists.php.net to get a copy of this message
On Tue, 5 Sep 2000, Jon Ribbens wrote: > I bet there are thousands of scripts out there that rely on variables > being unset at the start of their execution, that could be persuaded > to do bad things by setting the variables via CGI variables. I bet there > are thousands more which have bugs due to confusion as to where a variable > came from. Couldn't we instead implement warnings as in gcc which tell you if you use an unitialised variable? That way evil hackers couldn't overwrite our trusted variables. -- Bye, Peter Korsgaard

« previous php.dev (#32144) next »