At 06:30 PM 7/24/2004 +0200, Christian Schneider wrote:
And to understand the security impact:
include "./foo/bar/template_".$userinput;

... which I'd consider bad practice anyway but that's another story :-)

Yep. That person deserves to have his site hacked :)

Andi

--
PHP Internals - PHP Runtime Development Mailing List
To unsubscribe, visit: http://www.php.net/unsub.php



Reply via email to