Hello,
Just encountered an interesting thing while browsing Sugar plugins on SugarForge. From this example it seems that files with *.php extension get executed on the dl.sugarforge.org server instead of raw output. This may cause a security risk.
Hello,
Just encountered an interesting thing while browsing Sugar plugins on SugarForge. From this example it seems that files with *.php extension get executed on the dl.sugarforge.org server instead of raw output. This may cause a security risk.
There are currently 1 users browsing this thread. (0 members and 1 guests)
Bookmarks