Go to the FreeLists Home Page Home Signup Help Login
 



[dokuwiki] || [Date Prev] [09-2006 Date Index] [Date Next] || [Thread Prev] [09-2006 Thread Index] [Thread Next]

[dokuwiki] fixing clientIP() (was: SECURITY WARNING)

  • From: Andreas Gohr <andi@xxxxxxxxxxxxxx>
  • To: dokuwiki@xxxxxxxxxxxxx
  • Date: Fri, 08 Sep 2006 14:40:54 +0200

so to sum it up the vulnerability is in dwpage.php but cleaning the ip is a good idea anyway (it's already done in the current devel I think).
It was Sep 3, darcs version I was using, so no its not done properly in the current version.

Hmm... are we talking about the clientIP() function?

This line should remove all nasty stuff, shouldn't it?

$ip[$i] = preg_replace('/[^0-9\.]+/','',$ip[$i]);

Or did I miss something?

Andi
--
DokuWiki mailing list - more info at
http://wiki.splitbrain.org/wiki:mailinglist




[ Home | Signup | Help | Login | Archives | Lists ]

All trademarks and copyrights within the FreeLists archives are owned by their respective owners.
Everything else ©2007 Avenir Technologies, LLC.