Menu

#1 No security or input validation

open
nobody
None
5
2003-06-13
2003-06-13
John Holmes
No

No input validation when creating soldiers allows for
cross site scripting problems. No security checks when
editing a soldier allows you to edit any soldier in the
database, regardless if they are in your unit.
Downloading the edit soldier form and changing the data
is all it takes...

Just a few things to think about... :)

CPT John Holmes

Discussion

  • Stephen Hamilton

    Logged In: YES
    user_id=776057

    Take a look at the new editsoldertng file. I believe it fixes
    this problem, since it is all permission based.

     
  • John Holmes

    John Holmes - 2003-09-04

    Logged In: YES
    user_id=609197

    Where is that file?

     
  • Stephen Hamilton

    Logged In: YES
    user_id=776057
    Originator: NO

    Fixed. Can only update soldiers within your company, and if you have permissions to edit soldiers.

    Thanks for the comment!

     

Log in to post a comment.