eestock again <solved>
Collins
erichey2
Mon May 17 11:57:36 PDT 2004
On Monday 29 December 2003 21:47, Ted Ozolins wrote:
> In PHP-4 "register_globals=Off" this prevented the PHP script to access
> postgresql's data. By changing this to "register_globals=On" allows the
> php script to do its magic. Whether this poses a security risk is
> unclear to me at this time.
It's quite clear in all the literature that this is a major security exposure.
You will wnat to report this to whoever crafted the script.
--
Collins
More information about the Linux-users
mailing list