Had a script kiddie hack attempt using the above method so I highly recommend not doing a dynamic header is this way.
Looking through my logs, vb.org was queried with the search term Joomla highlighted in order to find my site and run an automated exploit.
From another website on the same issue:
Quote:
The hacker is taking advantage of this global variables PHP exploit and inserting the URL of the code they run remotely into the URL so that they can run the program onto your server. How to fix the problem? Make it so the hacker can't pass URLs on your site.
|