Page MenuHomePhabricator

Check insertDefaultSites in Utils.php
Closed, ResolvedPublic

Description


Version: unspecified
Severity: normal
Whiteboard: storypoints: 2

Details

Reference
bz40551

Event Timeline

bzimport raised the priority of this task from to Needs Triage.Nov 22 2014, 12:44 AM
bzimport set Reference to bz40551.
bzimport added a subscriber: Unknown Object (MLST).

The way that you're passing in a function to insertDefaultSites in Utils.php makes a security evaluation difficult. I'm not sure what your intent was behind that syntax, but it would be better to either have a whitelist of function names, or possibly use the builtin debugging functions if you're only trying to get debugging information.

Fixed by Tim Starling in I394c33f3ef06d09bae32fa875a33c93b3131daed

Verified in Wikidata demo time for sprint 18