"Benjamin Lees" <[email protected]> wrote in message 
news:[email protected]...
> In the line
> function parsePHP( $input, $argv, &$parser ) { return runphpExecCode(
> $input, $argv ); }
> Change &$parser to $parser

And then maybe delete that whole line, and all the other lines in the file? 
On your head be it, obviously, but I can't think of *any* scenario in which 
I'd use this extension, or recommend anyone else do so.  Being on an 
intranet or being restricted-account-creation will not protect your wiki 
against XSS vulnerabilities that are commonly found in MediaWiki and other 
software, and here you're basically trusting the security of your entire 
filesystem on the assumption that they will.

--HM 



_______________________________________________
Wikitech-l mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/wikitech-l

Reply via email to