|
Uhm, I was actually looking over the problematic piece of code a while
ago too, but I thought you could only retrieve JS scripts you where not
supposed to this way and I didn't consider it much of a security issue.
Good that it has been fixed and that we have some people who like to
look at the security aspects in the framework. Best Regards, Felix Geisendörfer Larry E. Masters aka PhpNut schrieb: There was an security exploit brought to my attention today. I have fixed this exploit in the trunk and branched versions. Please replace the app/webroot/js/vendors.php with this file. --~--~---------~--~----~------------~-------~--~----~ You received this message because you are subscribed to the Google Groups "Cake PHP" group. To post to this group, send email to [email protected] To unsubscribe from this group, send email to [EMAIL PROTECTED] For more options, visit this group at http://groups.google.com/group/cake-php -~----------~----~----~----~------~----~------~--~--- |
- Security Exploit. Larry E. Masters aka PhpNut
- Re: Security Exploit. Felix Geisendörfer
- Re: Security Exploit. [EMAIL PROTECTED]
- Re: Security Exploit. [EMAIL PROTECTED]
- Re: Security Exploit. John David Anderson (_psychic_)
- Re: Security Exploit. Larry E. Masters aka PhpNut
- Re: Security Exploit. Felix Geisendörfer
