Re: hmmm
This WebDNA talk-list message is from 2006
It keeps the original formatting.
numero = 67352
interpreted = N
texte = John Peacock wrote:> Jesse Proudman wrote:>> [This was reported to SM a week or two ago]>>>> On a security note...>>>> http://www.smithmicro.com/?text=&!=&math=>>Actually, turning off "Display Error Message" in Preferences seems to help some (if you cannot directly filter those requests).We can infer that what is happening is the automatic formvariable to context code is firing for "!" and "text" and "math" and if you have one of those contexts in an include file or template, the substitution code will break your existing code (by eating the initial [!] or [text] or [math] tag), and the remainder of your template or include file will be displayed as is in the page.This is an incredibly big deal. I'm going to go through all of the other paired contexts ([context][/context]) and see whether those are affected as well...John-- John PeacockDirector of Information Research and TechnologyRowman & Littlefield Publishing Group4501 Forbes BoulevardSuite HLanham, MD 20706301-459-3366 x.5010fax 301-429-5748-------------------------------------------------------------This message is sent to you because you are subscribed to the mailing list
.To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://webdna.smithmicro.com/
Associated Messages, from the most recent to the oldest:
John Peacock wrote:> Jesse Proudman wrote:>> [This was reported to SM a week or two ago]>>>> On a security note...>>>> http://www.smithmicro.com/?text=&!=&math=>>Actually, turning off "Display Error Message" in Preferences seems to help some (if you cannot directly filter those requests).We can infer that what is happening is the automatic formvariable to context code is firing for "!" and "text" and "math" and if you have one of those contexts in an include file or template, the substitution code will break your existing code (by eating the initial [!] or [text] or [math] tag), and the remainder of your template or include file will be displayed as is in the page.This is an incredibly big deal. I'm going to go through all of the other paired contexts ([context][/context]) and see whether those are affected as well...John-- John PeacockDirector of Information Research and TechnologyRowman & Littlefield Publishing Group4501 Forbes BoulevardSuite HLanham, MD 20706301-459-3366 x.5010fax 301-429-5748-------------------------------------------------------------This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://webdna.smithmicro.com/
John Peacock
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
Simple way to create unique SKU (1997)
Webdna 5.0 reference documentation (2003)
Tax & Shipping (1997)
WebDNA Codes in Secure Mode (1997)
Mozilla/4. and Browser Info.txt (1997)
Show shoppingcart after remove last item (1997)
WebCat2 - Getting to the browser's username/password data (1997)
Here's how to kill a Butler Database. (1997)
[WebDNA] behavior of [thisurl] in the context of 'mod_rewrite' (2012)
Mac: LModelDirector bug fix (1997)
Slide Show (2002)
Math variable size-dumb question (1999)
U&P IIS concept (1998)
[ShowNext] (1997)
Help name our technology! (1997)
Caching [include] files ... (1997)
Location of Browser Info.txt file (1997)
Initiating NewCart (1997)
dates and hex formatting (1997)
Password Authentication - request example (1998)