We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 21255
    • 215 Posts
    Quote from: PrisonerOfPain at Apr 27, 2006, 10:02 AM

    The unregister globals part is insecure. If I call the code with, say, index.php?modx=0 and register globals was on. Then the code just deleted our $modx variable.

    Ow, and the cleanup function is still prone to XSS. If, for example, a GPC value would contain <a onmouseover="doEvilDeeds()"> the script would fail, and I’d still be able to inject your site. (At least, as far as I can tell by looking at the code).

    The code isn’t intended to prevent XSS attacks through GPC. There’s no reason to.

    It’s absolutely okay to unset $myvariable, $modx, or whatever since the code occurs in the very first lines of index.php
      • 23879
      • 18 Posts
      Quote from: netnoise at Apr 27, 2006, 10:51 AM

      It’s absolutely okay to unset $myvariable, $modx, or whatever since the code occurs in the very first lines of index.php
      Seems like a valid point you’ve got there wink.
        • 1564
        • 31 Posts
        Did this security patch get included in the core? Or should I think about adding the script.. Thank you very much for advice!
          MODx is way ahead... Thanks for your work!