3 ms·
How can a zero-day be well documented? By definition it's not yet public.
by emillon 13y ago
How can a zero-day be well documented? By definition it's not yet public.
- meritt 13y agoIt sounds scarier than saying: "If you use PHP, remember to set the following in your .ini" cgi.fix_pathinfo = 0
- jonknee 13y agoSo not zero day and not an exploit. A terrible idea for a feature though, PHP seems to be rich with those.
- meritt 13y agoNot really a terrible idea at all. They are simply conforming to the CGI specification. In realizing the potential security issues associated with doing so, they offer a way to disable that behavior.