Emtatsheni wezincwadi
Umtapo wolwazi wathuthukiswa abadali be-CMS TYPO3, kodwa uphinde usetshenziswe kumaphrojekthi we-Drupal ne-Joomla, okuwenza nawo abe sengozini yokuba sengozini. Inkinga ilungisiwe ekukhishweni
Ngasohlangothini olungokoqobo, ukuba sengozini ku-PharStreamWapper kuvumela umsebenzisi we-Drupal Core onezimvume 'Zokuphatha itimu' ukuthi alayishe ifayela le-phar eliyingozi futhi abangele ukuthi ikhodi ye-PHP equkethwe kuyo isetshenziswe ngaphansi kokucasha kwengobo yomlando ye-phar esemthethweni. Khumbula ukuthi ingqikithi yokuhlasela kwe-“Phar deserialization” ukuthi uma ubheka amafayela osizo alayishiwe omsebenzi we-PHP file_exists(), lo msebenzi ususa ngokuzenzakalelayo imethadatha kumafayela e-Phar (PHP Archive) lapho ucubungula izindlela eziqala ngokuthi “phar://” . Kungenzeka ukudlulisa ifayela le-phar njengesithombe, njengoba umsebenzi we-file_exists() unquma uhlobo lwe-MIME ngokuqukethwe, hhayi ngokwesandiso.
Source: opennet.ru