Re: PHP class files without <?php at the top

From: Date: Mon, 09 Apr 2012 10:27:44 +0000
Subject: Re: PHP class files without <?php at the top
References: 1 2 3 4 5 6  Groups: php.internals 
Request: Send a blank email to [email protected] to get a copy of this message
On 08/04/12 14:31, Tom Boutell wrote:
> This is an attempt to protect people who have written inherently insecure code anyway. One
> should never do a dynamic require to any untrusted location, if ever at all, yes? 
>
Obviously.  But that include vulnerabilty seems a precondition to the
scenario Yasuo tries to protect.



Thread (70 messages)

« previous php.internals (#59492) next »