» tagged pages
» logout

(Feed found, click Add Page to syndicate.) Error finding feed, please try again » Find feed title

A Blog Page allows you to add entries, for news or other time sensitive postings

(Login required to save to your tagged pages.)
(or Cancel)

Make further edits, (or Cancel)

(Login required to save to your tagged pages.)
(or Cancel)

(Editing anonymously: to be credited for your changes, login or register a new account)

Change Page Permissions? Changing these permissions will adjust who can modify this page.

Anonymous (change)
(change)
(or Cancel)
Upload an image from your computer:
or Copy an image from a URL:
or Erase the current icon:
Icon Preview:

or Cancel

Erase Evaluating? The contents of Evaluating page and all pages directly attached to Evaluating will be erased.

or Cancel

(Editing anonymously: to be credited for your changes, login or register a new account)

other page actions:
Evaluating

Evaluating

sorted by: recent | see : popular
Content Tagged Evaluating

Evaluating a PHPMailer Vulnerability

A report was submitted to the Mantis team this week describing a vulnerability in the PHPMailer class. This class is used by Mantis to send notification emails for issue updates.<br /> <br /> The exploit takes advantage of a hole in how PHP implements the internal interface to the sendmail MTA. The setting for the sender address can be used to gain access to system resources. This exploit is described in <a href="http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/">http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/</a> [<a href="http://larholm.com/2007/06/11/phpmailer-0day-remote-execution/" target="_blank">^</a>] and <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3215">http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3215</a> [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3215" target="_blank">^</a>] .<br /> <br /> After reviewing the Mantis code, we determined that this vulnerability does not affect the operation of the tool. We read the sender address from configuration data. To use this exploit, someone would require administrator level access and/or direct access to the database. The probability of exploit is very low. A small patch will be added in the next release to prevent the problem completely.<br /> <br /> In general, we recommend using the SMTP mode, rather than sendmail, rather than the local sendmail implementation. Most platforms, (Windows, especially), have problems with the internal PHP implementation of the sendmail. The PHPMailer implementation of SMTP is more robust and slightly faster.

mantis: Mantis News

uwem

The Unified Web Evaluation Methodology (UWEM) is the result of a joint effort by 23 European organisations in three European projects combined in a cluster to develop a harmonized methodology for evaluating the accessibility of web sites. UWEM defines a sampling method, tests to check conformance against WCAG 1.0 checkpoints (priority 1 and 2), an aggregation method for test results, and templates for reporting the results.

Know your sources: Evergreen / Koha comparisons - Coffee|Code

"How many other libraries are currently using this feature? Is this feature part of the base package, or is it an optional extra that's going to cost me more? Is this a massive feature that hasn't been broken down into sub-features?""It's all about trusti

opensource: del.icio.us tag/opensource

Page 1 | Next >>
Username:
Password:
(or Cancel)