Re: [phorum-dev] Security flaw in Phorum 3.1 and higher
| From: | Jason Birch | Date: | Wed, 22 Nov 2000 06:38:58 +0000 |
| Subject: | Re: [phorum-dev] Security flaw in Phorum 3.1 and higher | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-26588@lists.php.net to get a copy of this message | ||
Just a note. That code snippet is in the common.php file.
Jason
On Tue, 21 Nov 2000 22:18:48 -0600, "Brian Moon" <brian@phorum.org>
spoke:
> A serious security hole has been discovered in Phorum versions 3.1 and
> higher. A 3.2.7 package will be available by morning. It will include this
> fix along with a number of other bug fixes. In the meantime, to fix the
> problem, find the lines like this:
>
> if($num || $f){
> if($f) $num=$f;
> if(file_exists("$admindir/forums/$num.php")){
>
> After the line 'if($f) $num=$f;' put:
>
> $num=(int)$num;
>
> I will not say here what the hole was, only that it could potentially allow
> sensitive configuration information to be displayed. Thanks to Jose Borges
> Ferreira for the report.
>
>
> Brian Moon
> --------------------------------------------------------------
> Phorum Dev Team - http://phorum.org
> Making better forums with PHP
> --------------------------------------------------------------
>
>
>
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: phorum-dev-unsubscribe@lists.phorum.org
> For additional commands, e-mail: phorum-dev-help@lists.phorum.org