6 Nov
2006
6 Nov
'06
10:30 p.m.
CVE-2006-5465 Stefan Esser discovered a buffer overflow in the htmlspecialchars() and htmlentities(), which might lead to the execution of arbitrary code. check_plain and xmlrpc use htmlspecialchars. Heine