Skip to content
Snippets Groups Projects
Commit 0100f1e8 authored by Susanne Moog's avatar Susanne Moog Committed by Oliver Hader
Browse files

[SECURITY] Disallow pht as file extension

Some web servers allow and accept pht files as PHP files
and execute them. Thus, pht should be part of the default
file deny pattern and PHP file extensions.

Resolves: #82078
Releases: master, 8.7, 7.6
Security-Commit: d7e19499bfa4bd552d4428a2b9a943005c20c61d
Security-Bulletin: TYPO3-CORE-SA-2017-007
Change-Id: Ibadcaa8c32b70b9aec569027862918d0360ec075
Reviewed-on: https://review.typo3.org/53904


Reviewed-by: default avatarOliver Hader <oliver.hader@typo3.org>
Tested-by: default avatarOliver Hader <oliver.hader@typo3.org>
parent c6498b2d
Branches
Tags
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment