Re: PHP File Upload Security Hole - Still No Fix?

From: Date: Wed, 06 Sep 2000 09:57:49 +0000
Subject: Re: PHP File Upload Security Hole - Still No Fix?
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-32334@lists.php.net to get a copy of this message
Ron Chmara <ron@opus1.com> wrote: > Warning level E_ALL does just this, but the problem wasn't an uninitialized > variable. It was initialized, with dangeous data.... (see HTTP_*_VARS thread) True, but when the script author is developing their code, the variable *will* be uninitialised, they will see the warning, and they will fix their code. Then when later on an evil hacker comes along and initialises the variable, it won't matter.

« previous php.dev (#32334) next »