Gossamer Forum
Home : Products : DBMan : Discussions :

Re: Major Security Hole (fix incl)

Quote Reply
Re: Major Security Hole (fix incl) In reply to
Ok, I've been waiting around for someone to respond to this, but it does'nt look like it's going to happen, so I'll just go right ahead and ask:

Exactly how is this achieved? I tried a few things on my DB... no results...

Don't get me wrong, I'm not asking so I can go around and wreak havoc on every web server running DBMan, I'm asking because it does'nt exactly seem like there are too many people concerned about this.

I mean, only 50 views? and No replies?

The code reads:
$regexp_func[$field] = eval "sub { m/$tmpreg/o }";

Now my perl knowledge isn't great, but the way I see it, as long as we don't evaluate the string (add an 'e' modifier) we're fine...

I could be wrong, I probobly am... But could someone please verify this? Because it isn't exaclty like people are jumping around to spread the word, and if any possible security bug should be squished, it's this one.

- Mark

Astro-Boy!!
http://www.zip.com.au/~astroboy/
Subject Author Views Date
Thread Post deleted by ELB ELB 5554 Jun 15, 2000, 8:48 AM
Thread Re: Major Security Hole (fix incl)
AstroBoy 5363 Jun 20, 2000, 11:03 PM
Post Re: Major Security Hole (fix incl)
JPDeni 5392 Jun 20, 2000, 11:45 PM
Thread I probably shouldn't, but here's a hint
ELB 5354 Jun 21, 2000, 3:41 PM
Post Re: I probably shouldn't, but here's a hint
AstroBoy 5335 Jun 21, 2000, 6:42 PM
Post Re: Major Security Hole (fix incl)
Bearwithme 5300 Jun 22, 2000, 1:32 AM
Post Re: Major Security Hole (fix incl)
Stealth 5296 Jun 22, 2000, 6:18 PM
Thread Re: Major Security Hole (fix incl)
gusmelo 5143 Jul 4, 2000, 6:18 PM
Thread Re: Major Security Hole (fix incl)
Bearwithme 5184 Jul 4, 2000, 6:37 PM
Post oops, sorry. fix for my fix is forthcoming
ELB 5187 Jul 5, 2000, 8:27 AM