PmWiki »

Security

 

Deep dependencies

 

 

 

PmWiki

 

edit SideBar


Distributed Pages:

 

Cookbook Pages

 

 

 

 

What about the botnet security advisory at http://isc.sans.org/diary.php?storyid=1672?

 

Sites that are running with PHP's register_globals setting set to "On" and versions of PmWiki prior to 2.1.21 may be vulnerable to a botnet exploit that is taking advantage of a bug in PHP.  The vulnerability can be closed by turning register_globals off, upgrading to PmWiki 2.1.21 or later, or upgrading to PHP versions 4.4.3 or 5.1.4.  In addition, there is a test at PmWiki:SiteAnalyzer that can be used to determine if your site is vulnerable.

 

Page last modified on September 06, 2006, at 12:55 PM EST

Edit -
History -
Print -
Recent Changes
(All) -
Search