All releases tagged Major security fixes


Release Notes: All users of all versions of phplib should update to this version as soon as possible. Of major note is that in prepend.php3, the if() clause around $_PHPLIB['libdir'] assignment will allow a remote attacker to provide their own libdir (which can be remote), essentially allowing any person to inject any PHP code from anywhere into your PHPLIB-accessing script or site.