Re: com web/php: Fix potential file-include vulnerability: include/layout.inc

From: Date: Tue, 27 Jan 2015 01:02:56 +0000
Subject: Re: com web/php: Fix potential file-include vulnerability: include/layout.inc
References: 1  Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-20615@lists.php.net to get a copy of this message
is this actually used anywhere? -Hannes On Tue, Jan 20, 2015 at 1:10 PM, Peter Cowburn <salathe@php.net> wrote: > Commit: 686c4181e35c1b248dd95d502524cdc11a86c6d4 > Author: Anthony Ferrara <ircmaxell@gmail.com> Tue, 20 Jan 2015 16:10:19 -0500 > Parents: a4d873b05f0ea8ec26327bcccc645f051e15ca18 > Branches: master > > Link: > http://git.php.net/?p=web/php.git;a=commitdiff;h=686c4181e35c1b248dd95d502524cdc11a86c6d4 > > Log: > Fix potential file-include vulnerability > > Fix potential file-include vulnerability by adding EXTR_SKIP to > extract so it doesn't overwrite $params array. > > Changed paths: > M include/layout.inc > > > Diff: > diff --git a/include/layout.inc b/include/layout.inc > index 4b7d29e..9fc583b 100644 > --- a/include/layout.inc > +++ b/include/layout.inc > @@ -396,7 +396,7 @@ function print_view($templateName, array $params = array()) { > $path = $_SERVER['DOCUMENT_ROOT'] . '/views/' . $templateName; > if(file_exists($path)) { > if(!empty($params)) { > - extract($params); > + extract($params, EXTR_SKIP); > } > include_once $path; > } > > > -- > PHP Webmaster List Mailing List (http://www.php.net/) > To unsubscribe, visit: http://www.php.net/unsub.php >

« previous php.webmaster (#20615) next »