Sundar Rajan took the time to fully understand our PHP and mySQL programming needs and made the modifications exactly as required and within the time promised. You cannot ask for more than that kind of efficiency. We would highly recommend Sundar for your programming and development needs. He was excellent to work with.
The PHP development team would like to announce the immediate availability of PHP 5.4.3 and PHP 5.3.13. All users are encouraged to upgrade to PHP 5.4.3 or PHP 5.3.13 The releases complete a fix for a vulnerability in CGI-based setups (CVE-2012-2311). Note: mod_php and php-fpm are not vulnerable to this attack. PHP 5.4.3 fixes a buffer overflow vulnerability […]
PHP 5.3.12/5.4.2 do not fix all variations of the CGI issues described in CVE-2012-1823. It has also come to our attention that some sites use an insecure cgiwrapper script to run PHP. These scripts will use $* instead of "$@" to pass parameters to php-cgi which causes a number of issues. Again, people using mod_php or php-fpm are not affected. One […]
There is a vulnerability in certain CGI-based setups (Apache+mod_php and nginx+php-fpm are not affected) that has gone unnoticed for at least 8 years. Section 7 of the CGI spec states: Some systems support a method for supplying a [sic] array of strings to the CGI script. This is only used in the case of an `indexed' query. This is identified by a […]
DevConf 2012 in Moscow, Russia on Jun 9 - Jun 10 DevConf is the ultimate meeting place for russian-speaking web-developers, combining several language-specific conferences under one roof. This year DevConf will include the following sections: DevConf::PHP(); DevConf::Perl(); DevConf::RoR(); DevConf::Python(); DevConf::Javascript(); Each section will feature […]
The PHP development team announces the immediate availability of PHP 5.3.11 and PHP 5.4.1. These releases focuses on improving the stability of the current PHP branches with over 60 bug fixes, some of which are security related. Security Enhancements for both PHP 5.3.11 and PHP 5.4.1: Fixed bug #54374 (Insufficient validating of upload name leading to corrup […]