Nuacht

Researchers urge developers to ban PHP SuperGlobal variables in applications. These variables are wide open to remote code execution, remote file inclusion and security bypasses.
The PHP development team addressed CVE-2011-4885 in PHP 5.3.9, which was released on Jan. 10.