Gossamer Forum
Home : Products : Links 2.0 : Discussions :

Ssecurity hole

Quote Reply
Ssecurity hole
Someone that are accessing your search system can execute malicious codes on your browser easily!!!

When someone input in the search box some code and submit, the code will be logged on an file. From admin section when admin enter in view search log the code will be executed. Shocked
---
Joao Felipe S. S. Orui

Last edited by:

jfsso: Jun 7, 2002, 9:57 PM
Quote Reply
Re: [jfsso] Ssecurity hole In reply to
What search log?

Could you show an example?

Last edited by:

Paul: Jun 8, 2002, 1:23 AM
Quote Reply
Re: [Paul] Ssecurity hole In reply to
http://yoursearchsite.com/...admin.cgi?view_log=1
if the user puts some malicious code in search box and then submit it, it will be available on search log (access admin.cgi?view_log=1) :) there is no html wrap :(
---
Joao Felipe S. S. Orui

Last edited by:

jfsso: Jun 8, 2002, 4:58 AM
Quote Reply
Re: [jfsso] Ssecurity hole In reply to
Theres no such thing as view_log
Quote Reply
Re: [jfsso] Ssecurity hole In reply to
Is this a modification you installed?

Andy (mod)
andy@ultranerds.co.uk
Want to give me something back for my help? Please see my Amazon Wish List
GLinks ULTRA Package | GLinks ULTRA Package PRO
Links SQL Plugins | Website Design and SEO | UltraNerds | ULTRAGLobals Plugin | Pre-Made Template Sets | FREE GLinks Plugins!
Quote Reply
Re: [jfsso] Ssecurity hole In reply to
The admin directory should be protected by .htaccess and .htpasswd in any case.