Menu

#3 Repository is vulnerable to mischief

open
nobody
5
2002-12-09
2002-12-09
texas_stu
No

If any user is logged in to the XMLTester, then he/she
has the ability to delete, modify, and add ANY
documentsor collections in the repository via the Xincon
interface. There is no role-based security integrated into
this interface. One short term option is to remove
these editing features from the Xincon code until
they can be secured, and force edits to occur
from the Xindice command line.

Discussion


Log in to post a comment.

MongoDB Logo MongoDB