WordPress.org

Make WordPress Core

Opened 14 years ago

Closed 14 years ago

Last modified 14 years ago

#3357 closed defect (bug) (fixed)

wp_die('GLOBALS overwrite attempt detected') before wp_die() included.

Reported by: AlanJCastonguay Owned by:
Milestone: 2.1 Priority: normal
Severity: minor Version: 2.1
Component: General Keywords: globals wp_die
Focuses: Cc:

Description

On line 8 of wp-settings.php, wp_die() is used to display a friendly error message if a key named GLOBALS is seen in the request array. Aka, someone is trying to inject variables into the global scope.
8: wp_die('GLOBALS overwrite attempt detected');

wp_die() is defined in WPINC/functions.php, which is required on line 130 of the same file. Thus, the call to wp_die() fails, as it is not yet defined.

Should probably by reverted to die(), similar to changeset:4072

Attachments (1)

diff_wp-settings-wpdie-globals.diff (480 bytes) - added by AlanJCastonguay 14 years ago.
diff reverting wp_die('GLOBALS...') to die().

Download all attachments as: .zip

Change History (3)

@AlanJCastonguay
14 years ago

diff reverting wp_die('GLOBALS...') to die().

#1 @ryan
14 years ago

  • Resolution set to fixed
  • Status changed from new to closed

(In [4464]) Use die() not wp_die(). Props AlanJCastonguay. fixes #3357

#2 @ryan
14 years ago

  • Milestone set to 2.1
Note: See TracTickets for help on using tickets.