osCommerce / oscommerce2

osCommerce Online Merchant v2.x
http://www.oscommerce.com
MIT License
281 stars 222 forks source link

Some risk to look like, openssl, mcrypt unserialize 2.4 or 2.3 #620

Open oitsuki opened 6 years ago

oitsuki commented 6 years ago

2.4 unserialize ; It will be interesting to look if it's safe or not. openssl_random_pseudo_bytes mcrypt_create_iv ... More informations on this file. https://github.com/kalessil/phpinspectionsea/blob/master/docs/security.md#exploiting-unserialize