logo

New Response

« Return to the blog entry

You are replying to:

    • avatar
    • YoGi
    • Posted on Fri 5 Aug 2005 03:27

    I don't like the idea to pass a ressource name to include thru the URL. It makes me think of.. well, the common flaw in some scripting languages where beginners set a filename as parameter (foo.php?inc=contact.php, which can easily be replaced with foo.php?inc=/etc/passwd).

    What if you got - like most of notes databases - an "All" view, through which people might discover sensitive data ? I guess it can lead to security issues.

Your Comments

Name:
E-mail:
(optional)
Website:
(optional)
Comment: