Search the web
Sign In
New User? Sign Up
xml-rpc · XML-RPC Discussion
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Show off your group to the world. Share a photo of your group with us.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
Security advisory: XML-RPC for PHP   Message List  
Reply | Forward Message #3626 of 6839 |
All releases up to and including version 1.0 of XML-RPC for PHP have a
serious security vulnerability, allowing hostile remote clients or
servers to execute arbitrary code on your machine.

It is of critical importance that if you run an XML-RPC server or client
using the XML-RPC for PHP code that you update immediately. Both client
and server installations are affected by this flaw. The file you need
to replace is "xmlrpc.inc"

New code, version 1.01, can be downloaded from SourceForge:

https://sourceforge.net/project/showfiles.php?group_id=34455

I am indebted to Dan Libby for informing me of this security flaw.

May I remind users that, as licensed, the code comes with absolutely no
warranty at all. If you intend to use this code the responsibility for
auditing it rests with you.

-- Edd




Tue Sep 25, 2001 6:52 pm

edd@...
Send Email Send Email

Attachment
attachment
Type:
application/pgp-signature
Forward
Message #3626 of 6839 |
Expand Messages Author Sort by Date

All releases up to and including version 1.0 of XML-RPC for PHP have a serious security vulnerability, allowing hostile remote clients or servers to execute...
Edd Dumbill
edd@...
Send Email
Sep 25, 2001
7:07 pm
Advanced

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help