Posted by Chung Leong on 11/09/51 11:31
I don't believe the worm is using a new vulnerability. There're
probably plenty of servers with out-of-date version of that component
to exploit. A serious issue with component-programming in PHP: The
chief reason to use existing components instead of writing your own
code is to save time. It's unrealistic to expect programmers to invest
the necessary time to monitor the various components for security
updates.
[Back to original message]
|