Modify ↓
Opened 16 years ago
Closed 16 years ago
#4713 closed defect (fixed)
ServerSideRedirectPlugin vulnerable to SQL injection
Reported by: | Owned by: | Martin Scharrer | |
---|---|---|---|
Priority: | normal | Component: | ServerSideRedirectPlugin |
Severity: | major | Keywords: | |
Cc: | Trac Release: | 0.11 |
Description
I believe the plugin as written is vulnerable to SQL injection attacks. I have attached a proposed fix.
Attachments (1)
Change History (2)
Changed 16 years ago by
Attachment: | serversideredirect.patch added |
---|
comment:1 Changed 16 years ago by
Resolution: | → fixed |
---|---|
Status: | new → closed |
Thank you so much for the hint and the patch. I applied it to the source in SVN.
Note: See
TracTickets for help on using
tickets.
Proposed fix of possible SQL injection vulnerability