security
| From: | Lukas Smith | Date: | Tue, 24 May 2005 11:19:33 +0000 |
| Subject: | security | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-37818@lists.php.net to get a copy of this message | ||
Hi,
as some of you may have noticed there were recently a bunch of security fixes made to pearweb in regards to usage of $_SERVER['PHP_SELF'] where usually $_SERVER['SCRIPT_NAME'] is actually what people should have been using.
See blog post by Sean for more details:
http://blog.phpdoc.info/archives/13-XSS-Woes.html#extended
I search on PEAR reveals alot of usage of PHP_SELF in examples and library code as well. I suggest that everybody give their packages a look and make sure that they are using PHP_SELF for one of the few proper reasons or change to SCRIPT_NAME when not.
regards,
Lukas Smith
smith@backendmedia.com
_______________________________
BackendMedia
www.backendmedia.com
berlin@backendmedia.com
Linn Zwoch Smith GbR
Pariser Str. 44
D-10707 Berlin
Tel +49 30 83 22 50 00
Fax +49 30 83 22 50 07