Last modified: 2011-04-30 01:16:50 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T19639, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 17639 - calmer register_globals warning
calmer register_globals warning
Status: RESOLVED WONTFIX
Product: MediaWiki
Classification: Unclassified
Documentation (Other open bugs)
1.14.x
All All
: Lowest trivial (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2009-02-23 18:53 UTC by Dan Jacobson
Modified: 2011-04-30 01:16 UTC (History)
1 user (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Dan Jacobson 2009-02-23 18:53:37 UTC
We see in RELEASE-NOTES:
= MediaWiki release notes =
Security reminder: MediaWiki does not require PHP's register_globals
setting since version 1.2.0. If you have it on, turn it *off* if you can.

ADD here also: MediaWiki will work, but your server is more exposed to PHP-based security vulnerabilities.

Just like you mention elsewhere in the file tree. Else one will worry.

In fact you might mention that not only will it work, it will also protect itself too.
Comment 1 Tim Starling 2009-02-25 03:16:52 UTC
We get extensions committed fairly regularly that are vulnerable with register_globals enabled. And until recently, the core web installer was vulnerable. I think it's well worth the worry.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links