Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <b47dd3ef53b551664a77712e18738441.squirrel@wm.kinkhorst.nl>
Date: Tue, 28 Oct 2008 09:43:17 +0100 (CET)
From: "Thijs Kinkhorst" <thijs@...ian.org>
To: oss-security@...ts.openwall.com
Cc: coley@...re.org
Subject: Re: CVE request phpmyadmin (Fwd: XSS in phpMyadmin)

On Mon, October 27, 2008 23:28, Hanno Böck wrote:
> No fix yet, works also in 3.0.1.

Do we still call things that require register_globals to be on a
'vulnerability'?

Register_globals has been advertised (including in the PHP documentation
of that option) as a very bad idea for many years now, it's turned off by
default since years aswell. Turning it on could be considered as knowingly
taking the risk on a certain class of exploits.

At least Debian doesn't provide any security support for these issues.


Thijs

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.