summaryrefslogtreecommitdiff
path: root/source3/web/cgi.c
diff options
context:
space:
mode:
authorKai Blin <kai@samba.org>2011-07-07 10:03:33 +0200
committerKarolin Seeger <kseeger@samba.org>2011-07-26 20:47:40 +0200
commitde91a834def9726cdf24007f18e028b761b57e83 (patch)
treed5c50122534ed55180234720f0cfbbc1e9feee4d /source3/web/cgi.c
parent11b4dec29c9306531e73d5f4c12f89934dd538b4 (diff)
downloadsamba-de91a834def9726cdf24007f18e028b761b57e83.tar.gz
s3 swat: Fix possible XSS attack (bug #8289)
Nobuhiro Tsuji of NTT DATA SECURITY CORPORATION reported a possible XSS attack against SWAT, the Samba Web Administration Tool. The attack uses reflection to insert arbitrary content into the "change password" page. This patch fixes the reflection issue by not printing user-specified content on the website anymore. Signed-off-by: Kai Blin <kai@samba.org> (cherry picked from commit 05fa09be5a801baa5d35014e2f54b46c1ff5466b)
Diffstat (limited to 'source3/web/cgi.c')
0 files changed, 0 insertions, 0 deletions