Added max_input_vars directive to prevent attacks based on hash collisions

This commit is contained in:
Dmitry Stogov 2011-12-15 10:31:02 +00:00
parent 0d1998e34f
commit b8a08bf263
3 changed files with 11 additions and 0 deletions

View File

@ -163,6 +163,11 @@ UPGRADE NOTES - PHP 5.3
xsl.security_prefs. This option will be marked as deprecated in 5.4 again.
Use the method XsltProcess::setSecurityPrefs($options) there.
- the following new directives were added
- max_input_vars - specifies how many GET/POST/COOKIE input variables may be
accepted. default value 1000.
=============
5. Deprecated
=============

View File

@ -457,6 +457,9 @@ max_input_time = 60
; http://php.net/max-input-nesting-level
;max_input_nesting_level = 64
; How many GET/POST/COOKIE input variables may be accepted
; max_input_vars = 1000
; Maximum amount of memory a script may consume (128MB)
; http://php.net/memory-limit
memory_limit = 128M

View File

@ -457,6 +457,9 @@ max_input_time = 60
; http://php.net/max-input-nesting-level
;max_input_nesting_level = 64
; How many GET/POST/COOKIE input variables may be accepted
; max_input_vars = 1000
; Maximum amount of memory a script may consume (128MB)
; http://php.net/memory-limit
memory_limit = 128M