PHP bug

John Dalbec jpdalbec at ysu.edu
Thu Feb 12 19:21:21 UTC 2004


Platform: Cross Platform
Title: Apache mod_php Global Variables Information Disclosure
Weakness
Description: Mod_PHP is an Apache module which allows for PHP
functionality in websites. The security flaw is present if the
parameter 'register_globals = on' in the php.ini. An attacker may
access some sensible information. PHP version 4.3.4 and prior are
known to be vulnerable.
Ref: http://bugs.php.net/bug.php?id=25753





More information about the fedora-legacy-list mailing list