June 18, 2002Viewed: 1139
Overview Example Solution Notes Links Overview The Exchange Project Preview Release 2.1 [released March 2001] contains a security issue which can be taken advantage of by using the global variable scope that PHP provides. The security issue concerns the following files: catalog/includes/include_once.php admin/includes/include_once.php The cause of the security issue is the $include_file variable. If either of the pages are requested directly through a client, the $include_file variable does not ...