3 ms·
Could still be if file_exist then read file despite where or what file , it's the 2nd most common security hole I have seen behind sql injection.
by cdevs 10y ago
Could still be if file_exist then read file despite where or what file , it's the 2nd most common security hole I have seen behind sql injection.
- kijin 10y agoThe script just preloads every file in a hard-coded directory into an associative array and uses isset() to check if the requested post exists. So no arbitrary file access, either.