eestock again <solved>

Collins erichey2
Mon May 17 11:57:36 PDT 2004


On Monday 29 December 2003 21:47, Ted Ozolins wrote:
> In PHP-4 "register_globals=Off" this prevented the PHP script to access
> postgresql's data. By changing this to "register_globals=On" allows the
> php script to do its magic. Whether this poses a security risk is
> unclear to me at this time. 

It's quite clear in all the literature that this is a major security exposure.  
You will wnat to report this to whoever crafted the script.

-- 
Collins





More information about the Linux-users mailing list