[imp] PHP security
   
    Jan Schneider
     
    jan@horde.org
       
    Wed, 27 Feb 2002 16:39:41 +0100
    
    
  
Zitat von "Donatas V." <vyzard@yahoo.com>:
> Look:
> http://security.e-matters.de/advisories/012002.html
> 
> I am not a PHP programmer,so how imp uploads
> attachments?Maybe it can be exploitable?
> Should people using IMP begin to worry?
Of course IMP just uses the PHP functionality for handling file uploads. So 
everyone using any PHP application that incorporates file uploads (like 
IMP) should update to be on the safe side.
>From php.net: "All users of PHP are strongly encouraged to either upgrade 
to PHP 4.1.2, or install the patch (available for PHP 3.0.18, 4.0.6 and 
4.1.0/4.1.1)."
Jan.
--
http://www.horde.org - The Horde Project
http://www.ammma.de - discover your knowledge
http://www.tip4all.de - Deine private Tippgemeinschaft