Gossamer Forum
Home : Products : DBMan : Discussions :

Re: Major Security Hole (fix incl)

Quote Reply
Re: Major Security Hole (fix incl) In reply to
Ok, I've been waiting around for someone to respond to this, but it does'nt look like it's going to happen, so I'll just go right ahead and ask:

Exactly how is this achieved? I tried a few things on my DB... no results...

Don't get me wrong, I'm not asking so I can go around and wreak havoc on every web server running DBMan, I'm asking because it does'nt exactly seem like there are too many people concerned about this.

I mean, only 50 views? and No replies?

The code reads:
$regexp_func[$field] = eval "sub { m/$tmpreg/o }";

Now my perl knowledge isn't great, but the way I see it, as long as we don't evaluate the string (add an 'e' modifier) we're fine...

I could be wrong, I probobly am... But could someone please verify this? Because it isn't exaclty like people are jumping around to spread the word, and if any possible security bug should be squished, it's this one.

- Mark

Astro-Boy!!
http://www.zip.com.au/~astroboy/
Subject Author Views Date
Thread Post deleted by ELB ELB 5550 Jun 15, 2000, 8:48 AM
Thread Re: Major Security Hole (fix incl)
AstroBoy 5358 Jun 20, 2000, 11:03 PM
Post Re: Major Security Hole (fix incl)
JPDeni 5388 Jun 20, 2000, 11:45 PM
Thread I probably shouldn't, but here's a hint
ELB 5350 Jun 21, 2000, 3:41 PM
Post Re: I probably shouldn't, but here's a hint
AstroBoy 5331 Jun 21, 2000, 6:42 PM
Post Re: Major Security Hole (fix incl)
Bearwithme 5296 Jun 22, 2000, 1:32 AM
Post Re: Major Security Hole (fix incl)
Stealth 5292 Jun 22, 2000, 6:18 PM
Thread Re: Major Security Hole (fix incl)
gusmelo 5138 Jul 4, 2000, 6:18 PM
Thread Re: Major Security Hole (fix incl)
Bearwithme 5179 Jul 4, 2000, 6:37 PM
Post oops, sorry. fix for my fix is forthcoming
ELB 5183 Jul 5, 2000, 8:27 AM