PHP filter_var Bypass Patch

Discussion in 'News Aggregator' started by Packet Storm, 30 Mar 2022.

  1. Packet Storm

    Packet Storm Guest

    When the filter_var function is used in conjunction with the flags FILTER_VALIDATE_DOMAIN and FILTER_FLAG_HOSTNAME, there is a vulnerability in PHP that allows the filter to be bypassed. A patch has been included by the researcher as the PHP security team seems to have ignored this concern.

    Continue reading...
     

Share This Page

Loading...