Vulnerability nyob rau hauv PHP uas tso cai rau koj mus hla kev txwv nyob rau hauv php.ini

Ib txoj hauv kev tau tshaj tawm los hla hauv tus neeg txhais lus PHP cov kev txwv uas tau teev tseg siv cov lus qhia disable_functions thiab lwm qhov chaw hauv php.ini. Cia peb nco qab tias cov lus qhia disable_functions ua rau nws tuaj yeem txwv tsis pub siv qee yam haujlwm sab hauv hauv cov ntawv sau, piv txwv li, koj tuaj yeem lov tes taw "system, exec, passthru, popen, proc_open thiab shell_exec" los thaiv kev hu mus rau lwm cov kev pab cuam lossis fopen txwv. qhib cov ntaub ntawv.

Nws yog ib qho tseem ceeb uas qhov kev thov siv tau siv qhov tsis zoo uas tau tshaj tawm rau PHP cov neeg tsim khoom ntau dua 10 xyoo dhau los, tab sis lawv suav tias nws yog qhov teeb meem me uas tsis muaj kev cuam tshuam txog kev nyab xeeb. Txoj kev tawm tsam tawm tsam yog ua raws li kev hloov pauv qhov tseem ceeb ntawm qhov tsis muaj nyob hauv cov txheej txheem nco thiab ua haujlwm hauv txhua qhov kev tshaj tawm PHP tam sim no, pib nrog PHP 7.0 (qhov kev tawm tsam kuj tseem ua tau ntawm PHP 5.x, tab sis qhov no yuav tsum tau hloov pauv rau kev siv) . Qhov kev siv tau raug sim ntawm ntau yam kev teeb tsa ntawm Debian, Ubuntu, CentOS thiab FreeBSD nrog PHP hauv daim ntawv cli, fpm thiab module rau apache2.

Tau qhov twg los: opennet.ru

Ntxiv ib saib