3 ms·
Mirrored patches: Drupal 6: https://gist.github.com/paragonie-scott/dca4690a504a1d860575041eb274eeef https://gist.github.com/paragonie-scott/dca4690a504a1d8605
by CiPHPerCoder 9y ago
Mirrored patches:
Drupal 6: https://gist.github.com/paragonie-scott/dca4690a504a1d860575041eb274eeef https://gist.github.com/paragonie-scott/dca4690a504a1d860575...
Drupal 7: https://gist.github.com/paragonie-scott/79ddffd734bf15a9d86b723d74d15572 https://gist.github.com/paragonie-scott/79ddffd734bf15a9d86b...
Drupal 8: https://gist.github.com/paragonie-scott/ee034dc43cbaafb9ff1cfcdda77d3240 https://gist.github.com/paragonie-scott/ee034dc43cbaafb9ff1c...
The actual mitigation of these patches: https://gist.github.com/paragonie-scott/79ddffd734bf15a9d86b723d74d15572#file-drupal-7-x-2018-002-patch-L91 https://gist.github.com/paragonie-scott/79ddffd734bf15a9d86b...
Explanation: https://twitter.com/codeincarnate/status/979080318966730753 https://twitter.com/codeincarnate/status/979080318966730753
> Drupal uses the hash "#" at the beginning of array keys to signify special keys usually that lead to some type of computation. Basically you can inject these. See Drupal form API for example