Re: hmmm
This WebDNA talk-list message is from 2006
It keeps the original formatting.
numero = 67356
interpreted = N
texte = Jesse Proudman wrote:> > It's a _huge_ security concern.I've confirmed through testing with the "Examples" page that any paired context ([context]something[/context]) can be broken by passing a null value as a URL value. If you use exclusively POST and not GET pages, you may be immune from this behavior (but it depends on your web server, since some will happily pass along URL parameters even to a POST).John-- John PeacockDirector of Information Research and TechnologyRowman & Littlefield Publishing Group4501 Forbes BoulevardSuite HLanham, MD 20706301-459-3366 x.5010fax 301-429-5748-------------------------------------------------------------This message is sent to you because you are subscribed to the mailing list
.To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://webdna.smithmicro.com/
Associated Messages, from the most recent to the oldest:
Jesse Proudman wrote:> > It's a _huge_ security concern.I've confirmed through testing with the "Examples" page that any paired context ([context]something[/context]) can be broken by passing a null value as a URL value. If you use exclusively POST and not GET pages, you may be immune from this behavior (but it depends on your web server, since some will happily pass along URL parameters even to a POST).John-- John PeacockDirector of Information Research and TechnologyRowman & Littlefield Publishing Group4501 Forbes BoulevardSuite HLanham, MD 20706301-459-3366 x.5010fax 301-429-5748-------------------------------------------------------------This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://webdna.smithmicro.com/
John Peacock
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
To Err or Not Custom Error (1999)
View Source from cache (1997)
Hiding a subsection of text (2002)
Frames and WebCat (1997)
lookup problem (2000)
WebDNA and Virtual Servers (2003)
# fields limited? (1997)
WebCatalog 4.0 has been released! (2000)
[WebDNA] [announce] CICADA Gold Products (2009)
Update quantity (2000)
Here we go again... (2006)
refreshing IE with posted .tmpl (1997)
[TaxableTotal] - not working with AOL and IE (1997)
another problem (1997)
WebDNA on Redhat (2008)
total number of matches (1999)
Formatting date to number (2000)
Pre-flight public flag (1997)
formatting search results (1999)
File not found error message (1998)