Security flaw in Phorum 3.1 and higher

From: Date: Wed, 22 Nov 2000 04:18:48 +0000
Subject: Security flaw in Phorum 3.1 and higher
Groups: php.general 
Request: Send a blank email to php-general+get-26577@lists.php.net to get a copy of this message
A serious security hole has been discovered in Phorum versions 3.1 and higher. A 3.2.7 package will be available by morning. It will include this fix along with a number of other bug fixes. In the meantime, to fix the problem, find the lines like this: if($num || $f){ if($f) $num=$f; if(file_exists("$admindir/forums/$num.php")){ After the line 'if($f) $num=$f;' put: $num=(int)$num; I will not say here what the hole was, only that it could potentially allow sensitive configuration information to be displayed. Thanks to Jose Borges Ferreira for the report. Brian Moon -------------------------------------------------------------- Phorum Dev Team - http://phorum.org Making better forums with PHP --------------------------------------------------------------

« previous php.general (#26577) next »