DataLife Engine English Support Site » DatalifeEngine Help » Cross site scripting attack Flaw
Welcome,. Enter Username, or register.
Welcome,. Enter Username, or register.
ApadanaGroup's Hosting Services available now with Unbelievable LOW
PRICES,
Unlimited SPACE AND Unlimited Transfer ....Check it out !!!
http://unlimitpackage.net/
Cross site scripting attack Flaw
Problem: Insufficient variable
$_SERVER [?PHP_SELF”]
Affected versions: 4.5, 4.3, 4.2
Hazard level: Low
Open index.php find:
Replace with:
Affected versions: 4.5, 4.3, 4.2
Hazard level: Low
Open index.php find:
$config['http_home_url'] = str_replace ('index.php', '', $_SERVER['PHP_SELF']);
Replace with:
$config['http_home_url'] = str_replace ('index.php', '', htmlspecialchars(strip_tags($_SERVER['PHP_SELF'])));
Your are currently a guest on this site. Please click here to register
- views: 721
-
Print
|
|
| |
#2
sam_snead
sam_snead
Joined: 21.07.2006 | ICQ: --
#1
ViC
ViC
User Group: Member
you good, man!
thanks for all your hard work
vic

thanks for all your hard work
vic
Joined: 3.09.2006 | ICQ: --



Users: 1
User Group: Member