Re: [WebDNA] Date error
This WebDNA talk-list message is from 2017
It keeps the original formatting.
numero = 113634
interpreted = N
texte = 1229Yeah.. not the way I would have =93fixed=94 it. :-)DonovanOn Jun 22, 2017, at 6:59 PM, Stuart Tremain
wrote:> Turns out the WebDNA version is 8.1>=20> Putting &command=3Dshowcart in the url caused problems.>=20> Namely reporting it was version 6.2 (why that happens is beyond me)>=20> Created problems with [DATE %Y]=20>=20> I haven=92t investigated any other code to determine if there are any =other issues.>=20> I guess a left over of the =93fix=94 you referred to.>=20> Obviously the old insecure way of putting command and the db path in =the url has been outdated for many years but I guess that is what =happens when you are working on someones old code.>=20> Kind regards>=20> Stuart Tremain> Pharoah Lane Software> AUSTRALIA> webdna@idfk.com.au>=20>=20>=20>=20>=20>=20>> On 23 Jun 2017, at 01:15, Donovan Brooke wrote:>>=20>> Version 6.2 had some URL vulnerabilities that were =93fixed=94 (I use =quotes because it wasn=92t a graceful fix) in later versions. =20>>=20>>=20>> Donovan>>=20>>=20>>=20>> On Jun 21, 2017, at 5:51 PM, Stuart Tremain =wrote:>>=20>>> It turns out that there is some code in the url that is causing =WebDNA to have a problem.>>>=20>>> I have reported this to WebDNA.>>>=20>>> Kind regards>>>=20>>> Stuart Tremain>>> Pharoah Lane Software>>> AUSTRALIA>>> webdna@idfk.com.au>>>=20>>>=20>>>=20>>>=20>>>=20>>>=20>>>> On 22 Jun 2017, at 02:11, Brian Fries wrote:>>>>=20>>>> Sounds like you=92ve got a variable named =93DATE=94 defined =somewhere, overriding the [date] WebDNA tag.>>>>=20>>>> Could be a formvariable, text or math variable, DB field name, or =an ORDERFILE header.>>>>=20>>>> - Brian>>>>=20>>>>=20>>>>> On Jun 20, 2017, at 11:09 PM, Stuart Tremain =wrote:>>>>>=20>>>>> I have just come across this on a site I am working on.>>>>>=20>>>>> [DATE %Y] returns 06/21/2017%Y]>>>>>=20>>>>> I would expect it to return 2017>>>>>=20>>>>> WebDNA v 6.2, I don=92t know what OS it is on as I don=92t have =access outside the sandbox but I suspect CentOS.>>>>>=20>>>>>=20>>>>> Kind regards>>>>>=20>>>>> Stuart Tremain>>>>> Pharoah Lane Software>>>>> AUSTRALIA>>>>> webdna@idfk.com.au>>>>>=20>>>>=20>>>> --------------------------------------------------------- This =message is sent to you because you are subscribed to the mailing list =talk@webdna.us To unsubscribe, E-mail to: talk-leave@webdna.us archives: =http://www.webdna.us/page.dna?numero=3D55 Bug Reporting: =support@webdna.us>>>=20>>> --------------------------------------------------------- This =message is sent to you because you are subscribed to the mailing list =talk@webdna.us To unsubscribe, E-mail to: talk-leave@webdna.us archives: =http://www.webdna.us/page.dna?numero=3D55 Bug Reporting: =support@webdna.us>>=20>> --------------------------------------------------------->> This message is sent to you because you are subscribed to>> the mailing list talk@webdna.us>> To unsubscribe, E-mail to: talk-leave@webdna.us>> archives: http://www.webdna.us/page.dna?numero=3D55>> Bug Reporting: support@webdna.us>=20> --------------------------------------------------------- This message =is sent to you because you are subscribed to the mailing list =talk@webdna.us To unsubscribe, E-mail to: talk-leave@webdna.us archives: =http://www.webdna.us/page.dna?numero=3D55 Bug Reporting: =support@webdna.us---------------------------------------------------------This message is sent to you because you are subscribed tothe mailing list talk@webdna.usTo unsubscribe, E-mail to: talk-leave@webdna.usarchives: http://www.webdna.us/page.dna?numero=3D55Bug Reporting: support@webdna.us.
Associated Messages, from the most recent to the oldest:
1229Yeah.. not the way I would have =93fixed=94 it. :-)DonovanOn Jun 22, 2017, at 6:59 PM, Stuart Tremain wrote:> Turns out the WebDNA version is 8.1>=20> Putting &command=3Dshowcart in the url caused problems.>=20> Namely reporting it was version 6.2 (why that happens is beyond me)>=20> Created problems with [DATE %Y]=20>=20> I haven=92t investigated any other code to determine if there are any =other issues.>=20> I guess a left over of the =93fix=94 you referred to.>=20> Obviously the old insecure way of putting command and the db path in =the url has been outdated for many years but I guess that is what =happens when you are working on someones old code.>=20> Kind regards>=20> Stuart Tremain> Pharoah Lane Software> AUSTRALIA> webdna@idfk.com.au>=20>=20>=20>=20>=20>=20>> On 23 Jun 2017, at 01:15, Donovan Brooke wrote:>>=20>> Version 6.2 had some URL vulnerabilities that were =93fixed=94 (I use =quotes because it wasn=92t a graceful fix) in later versions. =20>>=20>>=20>> Donovan>>=20>>=20>>=20>> On Jun 21, 2017, at 5:51 PM, Stuart Tremain =wrote:>>=20>>> It turns out that there is some code in the url that is causing =WebDNA to have a problem.>>>=20>>> I have reported this to WebDNA.>>>=20>>> Kind regards>>>=20>>> Stuart Tremain>>> Pharoah Lane Software>>> AUSTRALIA>>> webdna@idfk.com.au>>>=20>>>=20>>>=20>>>=20>>>=20>>>=20>>>> On 22 Jun 2017, at 02:11, Brian Fries wrote:>>>>=20>>>> Sounds like you=92ve got a variable named =93DATE=94 defined =somewhere, overriding the [date] WebDNA tag.>>>>=20>>>> Could be a formvariable, text or math variable, DB field name, or =an ORDERFILE header.>>>>=20>>>> - Brian>>>>=20>>>>=20>>>>> On Jun 20, 2017, at 11:09 PM, Stuart Tremain =wrote:>>>>>=20>>>>> I have just come across this on a site I am working on.>>>>>=20>>>>> [DATE %Y] returns 06/21/2017%Y]>>>>>=20>>>>> I would expect it to return 2017>>>>>=20>>>>> WebDNA v 6.2, I don=92t know what OS it is on as I don=92t have =access outside the sandbox but I suspect CentOS.>>>>>=20>>>>>=20>>>>> Kind regards>>>>>=20>>>>> Stuart Tremain>>>>> Pharoah Lane Software>>>>> AUSTRALIA>>>>> webdna@idfk.com.au>>>>>=20>>>>=20>>>> --------------------------------------------------------- This =message is sent to you because you are subscribed to the mailing list =talk@webdna.us To unsubscribe, E-mail to: talk-leave@webdna.us archives: =http://www.webdna.us/page.dna?numero=3D55 Bug Reporting: =support@webdna.us>>>=20>>> --------------------------------------------------------- This =message is sent to you because you are subscribed to the mailing list =talk@webdna.us To unsubscribe, E-mail to: talk-leave@webdna.us archives: =http://www.webdna.us/page.dna?numero=3D55 Bug Reporting: =support@webdna.us>>=20>> --------------------------------------------------------->> This message is sent to you because you are subscribed to>> the mailing list talk@webdna.us>> To unsubscribe, E-mail to: talk-leave@webdna.us>> archives: http://www.webdna.us/page.dna?numero=3D55>> Bug Reporting: support@webdna.us>=20> --------------------------------------------------------- This message =is sent to you because you are subscribed to the mailing list =talk@webdna.us To unsubscribe, E-mail to: talk-leave@webdna.us archives: =http://www.webdna.us/page.dna?numero=3D55 Bug Reporting: =support@webdna.us---------------------------------------------------------This message is sent to you because you are subscribed tothe mailing list talk@webdna.usTo unsubscribe, E-mail to: talk-leave@webdna.usarchives: http://www.webdna.us/page.dna?numero=3D55Bug Reporting: support@webdna.us.
Donovan Brooke
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
Problems with Price field (1997)
Summary search -- speed (1997)
[WebDNA] slideshow (2008)
Tab Charactor (1997)
Can you do this??? and other stuff (1997)
webcat2b12 CGI -- Date comparisons (1997)
date formatting for CC card expiration date check (1998)
TaxTotal Problem (1997)
WebCat2b13 Mac plugin - [sendmail] and checkboxes (1997)
How did *you* learn Web Catalog? (2000)
WebCat2 - [SendNews] (1997)
[WebDNA] Sort by Row (2017)
+ character mystery (2003)
Grant, please help me ... (1997)
This list needs a digest: rant, rave... (1997)
MasterCounter and capitalization (1997)
ShowNext (1997)
AmEx, shipping (2000)
Providing hard copy of database to client (1997)
WebCatalog 4 Install Problems - Not Answered ?? (2000)