11
* About this Vulnerability:
Really, from now, protector module prevent to this kind of attacks, named Variables contaminations.
* About php flags:
In my web site explain me that i can configure each php.ini for each foder, but i cannot make a php.ini for all the site.
Need I to put php.ini in all the folders?
Or, are only a especial folders that need it?
I think, in root and each module root. Correct? or also in root_module/admin/ ?
This php.ini has included, only that:
Quote:
register_globals = off
allow_url_fopen = off
session.use_trans_sid = off
If i put this php.ini in mysite.com/modules/protector/admin/, protector says that all is Ok.
But i know that is not Ok