Opened 14 years ago
Closed 14 years ago
#1028 closed Defect (fixed)
Minor Vulnerability in DB Abstraction Layer
Reported by: | jbboehr | Owned by: | davea |
---|---|---|---|
Priority: | Trivial | Milestone: | Undetermined |
Component: | Web - Project | Version: | 6.10.58 |
Keywords: | Cc: |
Description
This probably can't be used to do much, but it's generally not considered a good thing.
DBNAME gets replaced with the database name in user input.
Screenshot from MilkyWay?@Home Web UI:
Attachments (1)
Change History (2)
Changed 14 years ago by
Attachment: | boinc-php-fun.png added |
---|
comment:1 Changed 14 years ago by
Resolution: | → fixed |
---|---|
Status: | new → closed |
Note: See
TracTickets for help on using
tickets.
(In [22748]) - web: remove DBNAME hack, which allowed users to see the DB name