Gossamer Forum
Home : Products : Gossamer Mail : Discussion :

Security Bug report 1.1.6

Quote Reply
Security Bug report 1.1.6
Hello Alex!

What a surprise to know how many times the cgis crashed and showed the errors + passwords to the browsers.

This happens when a user has already submitted a form and presses resubmit will see the secrets that he should'nt. The same happens with all the errors.

In the admin of the version I have shows 1.1.5 although the download showed 1.1.6!

Where and whats wrong?

Quote Reply
Re: Security Bug report 1.1.6 In reply to
Hi,

The version number did not get updated in the last change, it still reports 1.1.5.

I'm not sure what you mean about errors + passwords to the browser, the user would only see their own information. Also, if you see these errors, it means Gossamer Mail is not setup properly, regular user errors do not display any debug information.

Cheers,

Alex

--
Gossamer Threads Inc.
Quote Reply
Re: Security Bug report 1.1.6 In reply to
Hello Alex!

If the script is working fully correct, then it means also that it has been setup correct, I beleive. I have not changed anything in the installations.

The error occurs when the script cannot connect to the MySQL database. In this case it reveals the MySQL database and all other sensitive informations to the user.