[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

Re: Bug: committers can set arbitrary HTTP Headers on any file

From: Brian W. Fitzpatrick <fitz_at_red-bean.com>
Date: 2007-08-10 20:47:01 CEST

On 8/10/07, Ben Collins-Sussman <sussman@red-bean.com> wrote:
> Well, um, it might be a security hole. Look at this paper:
>
> http://www.cgisecurity.com/lib/whitepaper_httpresponse.pdf

And if I can set the body of the response to whatever I want, then
surely *that's* a security hole, no?

-Fitz

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@subversion.tigris.org
For additional commands, e-mail: dev-help@subversion.tigris.org
Received on Fri Aug 10 20:45:05 2007

This is an archived mail posted to the Subversion Dev mailing list.