Bug#404744: phpMyAdmin, HTTP response splitting and PHP version

2007-01-06 Thread Marc Delisle
Marc Delisle a écrit : Hi all, I was trying to reproduce this problem: http://www.securityfocus.com/archive/1/453432 and I just remembered that PHP itself, since 5.1.2, has a protection for this: http://www.php.net/ChangeLog-5.php "Fixed possible header injection by limiting each head

Bug#404744: phpMyAdmin, HTTP response splitting and PHP version

2007-01-06 Thread Marc Delisle
Hi all, I was trying to reproduce this problem: http://www.securityfocus.com/archive/1/453432 and I just remembered that PHP itself, since 5.1.2, has a protection for this: http://www.php.net/ChangeLog-5.php "Fixed possible header injection by limiting each header to a single line. (Ilia)"