|
|
Choosing A Webhost: |
Re: yet more suggestions for .73...: msg#00012cms.phpslash.devel
Hi, On Sat, 10 May 2003, Luis M wrote: > > ummm it seems that posting code to an article causes phpslash to parse the > code. This makes yet another suggestion for the future release: > > #. Do not parse code coming from articles. > > Things like having $php variables, or {VAR} containers for templates... They > should all be escaped if the text comes from an article. That could > potentially eliminate all types of cross-site scripting and sql-code > injection that <i>might</i> be lurking in the phpslash code... > Can you please give a very specific example what exactly you did to discover this (including html/exttrans/plain settings, phpversion, phpslash version, os version, browser, and a step-by-step regression) Does this happen every time? If so I'd like to fix this and get it out pronto. -n -- ------ nathan hruby nathan-MSHXTcNGJzS8rjiVs5Nzzw@xxxxxxxxxxxxxxxx ------ ------------------------------------------------------- Enterprise Linux Forum Conference & Expo, June 4-6, 2003, Santa Clara The only event dedicated to issues related to Linux enterprise solutions www.enterpriselinuxforum.com
|
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | yet more suggestions for .73..., Luis M |
|---|---|
| Next by Date: | Really dumb question, nathan r. hruby |
| Previous by Thread: | yet more suggestions for .73..., Luis M |
| Next by Thread: | Re: yet more suggestions for .73..., Joe Stewart |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
Free MagazinesCisco NewsReceive a free quarterly e-newsletter with exclusive articles on how Cisco IT uses its own products and solutions to enable the business. subscribe Systems Management News, the newspaper for IT systems administration and data center managers! Each issue of Systems Management News is chock-full of news and analysis to help you understand what's happening in your field. subscribe The Enterprise Newsweekly eWeek is the essential technology information source for builders of e-business. subscribe Oracle Magazine Oracle Magazine contains technology strategy articles, sample code, tips, Oracle and partner news, how to articles for developers and DBAs, and more. Oracle (NASDAQ: ORCL) is the world's largest enterprise software company. subscribe Total Telecom Total Telecom is "The Economist of the communications industry". subscribe |
Home
| advertise | OSDir is
an inevitable website.
|