Menu

#5 Parameter value not encoded

open
nobody
None
5
2008-09-28
2008-09-28
S Vickers
No

In users.asp the uid parameters on the Edit links are not encoded so, for example, User IDs containing ampersands are not properly passed (e.g. adduser.asp?uid=a&b should be adduser.asp?uid=a%26b).

Discussion


Log in to post a comment.

MongoDB Logo MongoDB