'Twas brillig, and Vadim Gabriel at 29/05/09 08:51 did gyre and gimble:
No he can't
Take a look at : http://zendframework.com/manual/en/zend.view.migration.html
so unless he explicitly specify the lfi protection to false the ../../../ method will not work on 1.8 and it's no recommended anyways.

Ahh my bad. I thought when I read that before that ithe LFI protection only kicked in when the view *started* with ../ but I guess my memory is playing tricks on me or I didn't fully read it properly the first time round!


--

Colin Guthrie
gmane(at)colin.guthr.ie
http://colin.guthr.ie/

Day Job:
  Tribalogic Limited [http://www.tribalogic.net/]
Open Source:
  Mandriva Linux Contributor [http://www.mandriva.com/]
  PulseAudio Hacker [http://www.pulseaudio.org/]
  Trac Hacker [http://trac.edgewall.org/]

Reply via email to