Update on the security vulnerability

Update on the recent security vulnerability

Posted on Tuesday, April 17, 2007

I just wanted to post a quick message about the recent security vulnerability in Pixaria now that it's been dealt with. The issue relates to a single file in Pixaria's resources/includes/ directory called class.Smarty.php and it will only affect systems where the 'register_globals' setting for PHP is turned on.

The vulnerability allows a hacker to include and execute malicious PHP code over the internet which can then be used to give the hacker access to the affected web server as if they owned it.

The fix works by preventing the class.Smarty.php file from including remote files. The next update to Pixaria will feature changes to all include files to prevent them from being called or executed individually in this way.

del.icio.us Digg it



Comments for this article

blog comments powered by Disqus