security

From: Date: Tue, 24 May 2005 11:19:33 +0000
Subject: security
Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-37818@lists.php.net to get a copy of this message
Hi, as some of you may have noticed there were recently a bunch of security fixes made to pearweb in regards to usage of $_SERVER['PHP_SELF'] where usually $_SERVER['SCRIPT_NAME'] is actually what people should have been using. See blog post by Sean for more details: http://blog.phpdoc.info/archives/13-XSS-Woes.html#extended I search on PEAR reveals alot of usage of PHP_SELF in examples and library code as well. I suggest that everybody give their packages a look and make sure that they are using PHP_SELF for one of the few proper reasons or change to SCRIPT_NAME when not. regards, Lukas Smith smith@backendmedia.com _______________________________ BackendMedia www.backendmedia.com berlin@backendmedia.com Linn Zwoch Smith GbR Pariser Str. 44 D-10707 Berlin Tel +49 30 83 22 50 00 Fax +49 30 83 22 50 07

« previous php.pear.dev (#37818) next »