[dev] turn off allow_url_include in core.php

duck duck at obala.net
Sat Feb 14 09:24:26 UTC 2009


On Saturday 14 February 2009 05:26:36 Chuck Hagenbuch wrote:
> to the other ini settings in lib/core.php, as another security check?

I agree. But we should implement curl in Horde_Http_Client and other parts 
where we read remote streams.

Duck


More information about the dev mailing list