short of a bug in esc_like(), i don't even see the vulnerability issue in that code? that sanitize call looks like a data corruption issue and i bet it fails to search for binary data, but i don't see the critical vulnerability?
- Re: [PHP-DEV] [RFC] [VOTE] is_literal Dik Takken
- Re: [PHP-DEV] [RFC] [VOTE] is_literal Nikita Popov
- Re: [PHP-DEV] [RFC] [VOTE] is_literal Craig Francis
- Re: [PHP-DEV] [RFC] [VOTE] is_literal Joe Watkins
- Re: [PHP-DEV] [RFC] [VOTE] is_literal Máté Kocsis
- Re: [PHP-DEV] [RFC] [VOTE] is_literal Nikita Popov
- Re: [PHP-DEV] [RFC] [VOTE] is_literal Lauri Kenttä
- Re: [PHP-DEV] [RFC] [VOTE] is_literal Craig Francis
- Re: [PHP-DEV] [RFC] [VOTE] is_literal Craig Francis
- Re: [PHP-DEV] [RFC] [VOTE] is_literal Craig Francis
- Re: [PHP-DEV] [RFC] [VOTE] is_literal Hans Henrik Bergan
- Re: [PHP-DEV] [RFC] [VOTE] is_literal Craig Francis
- Re: [PHP-DEV] [RFC] [VOTE] is_literal Hans Henrik Bergan
- Re: [PHP-DEV] [RFC] [VOTE] is_lit... Craig Francis
- Re: [PHP-DEV] [RFC] [VOTE] is_literal Guilliam Xavier
- Re: [PHP-DEV] [RFC] [VOTE] is_lit... Craig Francis
- Re: [PHP-DEV] [RFC] [VOTE] is_literal Marco Pivetta
- Re: [PHP-DEV] [RFC] [VOTE] is_literal Craig Francis
- Re: [PHP-DEV] [RFC] [VOTE] is_literal Jordan LeDoux
- Re: [PHP-DEV] [RFC] [VOTE] is_literal AllenJB
- Re: [PHP-DEV] [RFC] [VOTE] is_literal Jordan LeDoux