Re: PHP File Upload Security Hole - Still No Fix?
| From: | Jon Ribbens | Date: | Wed, 06 Sep 2000 09:57:49 +0000 |
| Subject: | Re: PHP File Upload Security Hole - Still No Fix? | ||
| References: | 1 2 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-32334@lists.php.net to get a copy of this message | ||
Ron Chmara <ron@opus1.com> wrote:
> Warning level E_ALL does just this, but the problem wasn't an uninitialized
> variable. It was initialized, with dangeous data.... (see HTTP_*_VARS thread)
True, but when the script author is developing their code, the variable
*will* be uninitialised, they will see the warning, and they will fix
their code. Then when later on an evil hacker comes along and initialises
the variable, it won't matter.