Gossamer Forum
Home : Gossamer Threads Inc. : Official Bug Fixes :

Re: [brewt] [Links SQL 2.x/GLinks 3.0.0] Minor XSS Vulnerability

Quote Reply
Re: [brewt] [Links SQL 2.x/GLinks 3.0.0] Minor XSS Vulnerability In reply to
brewt wrote:
If your directory does not allow html in any link info (eg. link descriptions, reviews, etc) then you can not modify your templates and just add an option to GT::Template to html escape all variables. To do this, edit admin/Links.pm (it's on a different line depending on the version you have installed) in "sub user_page", before it calls GT::Template->parse(...), add the following line:
Code:
$opts->{escape} = 1;

And what can I do if I use html?
I am using Links SQL 2.1.2 and would not like to
update to Links 3.

Best regards from
Bremen/Germany

Lothar
Subject Author Views Date
Thread [Links SQL 2.x/GLinks 3.0.0] Minor XSS Vulnerability brewt 60671 Apr 21, 2005, 2:03 PM
Thread Post deleted by Alba
Alba 59648 Apr 22, 2005, 3:01 AM
Post Re: [Alba] [Links SQL 2.x/GLinks 3.0.0] Minor XSS Vulnerability
Andy 59618 Apr 22, 2005, 3:17 AM
Thread Re: [brewt] [Links SQL 2.x/GLinks 3.0.0] Minor XSS Vulnerability
pugdog 59614 Apr 22, 2005, 6:55 AM
Thread Re: [pugdog] [Links SQL 2.x/GLinks 3.0.0] Minor XSS Vulnerability
brewt 59604 Apr 22, 2005, 12:32 PM
Thread Re: [brewt] [Links SQL 2.x/GLinks 3.0.0] Minor XSS Vulnerability
Alba 59561 Apr 26, 2005, 7:34 AM
Thread Re: [Alba] [Links SQL 2.x/GLinks 3.0.0] Minor XSS Vulnerability
brewt 59534 Apr 26, 2005, 4:28 PM
Thread Re: [brewt] [Links SQL 2.x/GLinks 3.0.0] Minor XSS Vulnerability
Alba 59532 Apr 27, 2005, 1:03 AM
Thread Re: [Alba] [Links SQL 2.x/GLinks 3.0.0] Minor XSS Vulnerability
brewt 59586 Apr 27, 2005, 1:08 AM
Thread Re: [brewt] [Links SQL 2.x/GLinks 3.0.0] Minor XSS Vulnerability
pugdog 59510 Apr 27, 2005, 6:46 AM
Thread Re: [pugdog] [Links SQL 2.x/GLinks 3.0.0] Minor XSS Vulnerability
brewt 59527 Apr 27, 2005, 11:13 AM
Post Re: [brewt] [Links SQL 2.x/GLinks 3.0.0] Minor XSS Vulnerability
webmaster33 59490 Apr 28, 2005, 5:18 AM
Thread Re: [brewt] [Links SQL 2.x/GLinks 3.0.0] Minor XSS Vulnerability
eljot 55279 May 5, 2008, 11:43 PM
Post Re: [eljot] [Links SQL 2.x/GLinks 3.0.0] Minor XSS Vulnerability
brewt 55205 May 5, 2008, 11:59 PM