The Artima Developer Community
Sponsored Link

Python Buzz Forum
Important TurboGears 1.x Security Notice

0 replies on 1 page.

Welcome Guest
  Sign In

Go back to the topic listing  Back to Topic List Click to reply to this topic  Reply to this Topic Click to search messages in this forum  Search Forum Click for a threaded view of the topic  Threaded View   
Previous Topic   Next Topic
Flat View: This topic has 0 replies on 1 page
Mark Ramm

Posts: 404
Nickname: markramm
Registered: Mar, 2006

Mark Ramm is an generalist at heart, who programs Python for fun and profit.
Important TurboGears 1.x Security Notice Posted: Jan 14, 2008 3:43 PM
Reply to this message Reply

This post originated from an RSS feed registered with Python Buzz by Mark Ramm.
Original Post: Important TurboGears 1.x Security Notice
Feed Title: Compound Thinking
Feed URL: http://compoundthinking.com/blog/index.php/category/programming/python/turbogears/feed/
Feed Description: TurboGears related thoughts thoughts
Latest Python Buzz Posts
Latest Python Buzz Posts by Mark Ramm
Latest Posts From Compound Thinking

Advertisement
Most TurboGears users are not effected, but all TurboGears users who have explicitly added CherryPy based sessions to their application are subject to an important security vulnerability. Malicious users could create a specially crafted cookie that could delete files beginning with your SESSION_PREFIX from your file system, add new files with that prefix, or overwrite files [...]

Read: Important TurboGears 1.x Security Notice

Topic: Speaking of, "lying through their teeth..." Previous Topic   Next Topic Topic: What PHP Deployment Gets Right

Sponsored Links



Google
  Web Artima.com   

Copyright © 1996-2019 Artima, Inc. All Rights Reserved. - Privacy Policy - Terms of Use