Remediate other vulns

This commit is contained in:
Josh North 2021-08-11 10:54:25 -04:00
parent 28d8e418ed
commit e9e8a35c3e
22 changed files with 94 additions and 23 deletions

View File

@ -15,4 +15,12 @@
* You should have received a copy of the GNU General Public License * You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>. * along with this program. If not, see <http://www.gnu.org/licenses/>.
*/ */
ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION
ini_set('session.gc_probability', 1); // GC RATES
ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax');

View File

@ -15,4 +15,12 @@
* You should have received a copy of the GNU General Public License * You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>. * along with this program. If not, see <http://www.gnu.org/licenses/>.
*/ */
ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION
ini_set('session.gc_probability', 1); // GC RATES
ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax');

View File

@ -20,6 +20,7 @@
ini_set('session.gc_divisor', 100); // TIMES ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1'); ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1'); ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0'); ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0'); ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax'); ini_set('session.cookie_samesite', 'Lax');

View File

@ -15,4 +15,12 @@
* You should have received a copy of the GNU General Public License * You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>. * along with this program. If not, see <http://www.gnu.org/licenses/>.
*/ */
ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION
ini_set('session.gc_probability', 1); // GC RATES
ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax');

View File

@ -15,4 +15,12 @@
* You should have received a copy of the GNU General Public License * You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>. * along with this program. If not, see <http://www.gnu.org/licenses/>.
*/ */
ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION
ini_set('session.gc_probability', 1); // GC RATES
ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax');

View File

@ -15,12 +15,12 @@
* You should have received a copy of the GNU General Public License * You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>. * along with this program. If not, see <http://www.gnu.org/licenses/>.
*/ */
ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION
ini_set('session.gc_probability', 1); // GC RATES ini_set('session.gc_probability', 1); // GC RATES
ini_set('session.gc_divisor', 100); // TIMES ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1'); ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1'); ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0'); ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0'); ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax'); ini_set('session.cookie_samesite', 'Lax');

View File

@ -15,4 +15,12 @@
* You should have received a copy of the GNU General Public License * You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>. * along with this program. If not, see <http://www.gnu.org/licenses/>.
*/ */
ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION
ini_set('session.gc_probability', 1); // GC RATES
ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax');

View File

@ -15,12 +15,12 @@
* You should have received a copy of the GNU General Public License * You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>. * along with this program. If not, see <http://www.gnu.org/licenses/>.
*/ */
ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION
ini_set('session.gc_probability', 1); // GC RATES ini_set('session.gc_probability', 1); // GC RATES
ini_set('session.gc_divisor', 100); // TIMES ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1'); ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1'); ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0'); ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0'); ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax'); ini_set('session.cookie_samesite', 'Lax');

View File

@ -15,12 +15,12 @@
* You should have received a copy of the GNU General Public License * You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>. * along with this program. If not, see <http://www.gnu.org/licenses/>.
*/ */
ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION
ini_set('session.gc_probability', 1); // GC RATES ini_set('session.gc_probability', 1); // GC RATES
ini_set('session.gc_divisor', 100); // TIMES ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1'); ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1'); ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0'); ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0'); ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax'); ini_set('session.cookie_samesite', 'Lax');

View File

@ -15,12 +15,12 @@
* You should have received a copy of the GNU General Public License * You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>. * along with this program. If not, see <http://www.gnu.org/licenses/>.
*/ */
ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION
ini_set('session.gc_probability', 1); // GC RATES ini_set('session.gc_probability', 1); // GC RATES
ini_set('session.gc_divisor', 100); // TIMES ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1'); ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1'); ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0'); ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0'); ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax'); ini_set('session.cookie_samesite', 'Lax');

View File

@ -15,12 +15,12 @@
* You should have received a copy of the GNU General Public License * You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>. * along with this program. If not, see <http://www.gnu.org/licenses/>.
*/ */
ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION
ini_set('session.gc_probability', 1); // GC RATES ini_set('session.gc_probability', 1); // GC RATES
ini_set('session.gc_divisor', 100); // TIMES ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1'); ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1'); ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0'); ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0'); ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax'); ini_set('session.cookie_samesite', 'Lax');

View File

@ -15,12 +15,12 @@
* You should have received a copy of the GNU General Public License * You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>. * along with this program. If not, see <http://www.gnu.org/licenses/>.
*/ */
ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION
ini_set('session.gc_probability', 1); // GC RATES ini_set('session.gc_probability', 1); // GC RATES
ini_set('session.gc_divisor', 100); // TIMES ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1'); ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1'); ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0'); ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0'); ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax'); ini_set('session.cookie_samesite', 'Lax');

View File

@ -15,12 +15,12 @@
* You should have received a copy of the GNU General Public License * You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>. * along with this program. If not, see <http://www.gnu.org/licenses/>.
*/ */
ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION
ini_set('session.gc_probability', 1); // GC RATES ini_set('session.gc_probability', 1); // GC RATES
ini_set('session.gc_divisor', 100); // TIMES ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1'); ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1'); ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0'); ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0'); ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax'); ini_set('session.cookie_samesite', 'Lax');

View File

@ -15,12 +15,12 @@
* You should have received a copy of the GNU General Public License * You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>. * along with this program. If not, see <http://www.gnu.org/licenses/>.
*/ */
ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION
ini_set('session.gc_probability', 1); // GC RATES ini_set('session.gc_probability', 1); // GC RATES
ini_set('session.gc_divisor', 100); // TIMES ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1'); ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1'); ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0'); ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0'); ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax'); ini_set('session.cookie_samesite', 'Lax');

View File

@ -15,12 +15,12 @@
* You should have received a copy of the GNU General Public License * You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>. * along with this program. If not, see <http://www.gnu.org/licenses/>.
*/ */
ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION
ini_set('session.gc_probability', 1); // GC RATES ini_set('session.gc_probability', 1); // GC RATES
ini_set('session.gc_divisor', 100); // TIMES ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1'); ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1'); ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0'); ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0'); ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax'); ini_set('session.cookie_samesite', 'Lax');

View File

@ -15,4 +15,12 @@
* You should have received a copy of the GNU General Public License * You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>. * along with this program. If not, see <http://www.gnu.org/licenses/>.
*/ */
ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION
ini_set('session.gc_probability', 1); // GC RATES
ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax');

View File

@ -15,4 +15,12 @@
* You should have received a copy of the GNU General Public License * You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>. * along with this program. If not, see <http://www.gnu.org/licenses/>.
*/ */
ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION
ini_set('session.gc_probability', 1); // GC RATES
ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax');

View File

@ -15,4 +15,12 @@
* You should have received a copy of the GNU General Public License * You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>. * along with this program. If not, see <http://www.gnu.org/licenses/>.
*/ */
ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION
ini_set('session.gc_probability', 1); // GC RATES
ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax');

View File

@ -15,4 +15,12 @@
* You should have received a copy of the GNU General Public License * You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>. * along with this program. If not, see <http://www.gnu.org/licenses/>.
*/ */
ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION
ini_set('session.gc_probability', 1); // GC RATES
ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax');

View File

@ -20,8 +20,7 @@
ini_set('session.gc_divisor', 100); // TIMES ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1'); ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1'); ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0'); ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0'); ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax'); ini_set('session.cookie_samesite', 'Lax');

View File

@ -15,12 +15,12 @@
* You should have received a copy of the GNU General Public License * You should have received a copy of the GNU General Public License
* along with this program. If not, see <http://www.gnu.org/licenses/>. * along with this program. If not, see <http://www.gnu.org/licenses/>.
*/ */
ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION ini_set('session.gc_maxlifetime', 24*60*60); // MIN SESSION
ini_set('session.gc_probability', 1); // GC RATES ini_set('session.gc_probability', 1); // GC RATES
ini_set('session.gc_divisor', 100); // TIMES ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1'); ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1'); ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0'); ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0'); ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax'); ini_set('session.cookie_samesite', 'Lax');

View File

@ -20,8 +20,7 @@
ini_set('session.gc_divisor', 100); // TIMES ini_set('session.gc_divisor', 100); // TIMES
ini_set('session.use_cookies', '1'); ini_set('session.use_cookies', '1');
ini_set('session.use_only_cookies', '1'); ini_set('session.use_only_cookies', '1');
ini_set('session.cookie_lifetime', '0');
ini_set('session.cookie_secure', '0'); ini_set('session.cookie_secure', '0');
ini_set('session.cookie_httponly', '0'); ini_set('session.cookie_httponly', '0');
ini_set('session.cookie_samesite', 'Lax'); ini_set('session.cookie_samesite', 'Lax');