Opened 15 years ago
Closed 15 years ago
#1028 closed Defect (fixed)
Minor Vulnerability in DB Abstraction Layer
| Reported by: | jbboehr | Owned by: | davea |
|---|---|---|---|
| Priority: | Trivial | Milestone: | Undetermined |
| Component: | Web - Project | Version: | 6.10.58 |
| Keywords: | Cc: |
Description
This probably can't be used to do much, but it's generally not considered a good thing.
DBNAME gets replaced with the database name in user input.
Screenshot from MilkyWay?@Home Web UI:
Attachments (1)
Change History (2)
Changed 15 years ago by
| Attachment: | boinc-php-fun.png added |
|---|
comment:1 Changed 15 years ago by
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Note: See
TracTickets for help on using
tickets.


(In [22748]) - web: remove DBNAME hack, which allowed users to see the DB name