PhpDig - Serious
Hi. If you use PHPDIG_ADM_AUTH in the config.php file, rather than say htaccess, to protect the admin directory, then it is possible for someone to directly access the spider.php file via a browser.
To fix this in versions 1.6.5 and 1.8.0 do the following. In spider.php find the following code and add the line indicated: PHP Code:
If you are using a version earlier than 1.6.5, then you will need to get a later version and apply the above patch. If you download version 1.6.5 or 1.8.0 after the date of this post, the above patch has already been applied. |
All times are GMT -8. The time now is 03:32 AM. |
Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright © 2001 - 2005, ThinkDing LLC. All Rights Reserved.