Oliver Hader

Results 62 comments of Oliver Hader

@emmanuelGuiton correct, it's not always safe... the current stub is strict here, the 1st parameter is always considered harmful - which leads to false-positives for `$result = print_r($_GET, true)` and...

By reading the PHP docs, it does not seem, that `LIBXML_NO_XXE` would be required to disable entity expansion that would be enabled implicitly be other constants. However, I guess it...