Posted by Janwillem Borleffs on 09/03/06 12:03
NoWhereMan wrote:
> would you please help me find any security flaw in this code (if any)?
> thank you so much
>
> http://paste.uni.cc/9829
>
I assume you have properly set your base dir restriction directive in your
php.ini file to handle cases where $_REQUEST['f'] would be defined as
'../someprivatedir/dbconnect.php'?
JW
Navigation:
[Reply to this message]
|