Copy link to clipboard
Copied
Copy link to clipboard
Copied
Copy link to clipboard
Copied
quote:
Originally posted by: Newsgroup User
they shouldn't be able to download your whole page- just the html part.
Hence- No functionality.
Copy link to clipboard
Copied
Copy link to clipboard
Copied
quote:
Originally posted by: Newsgroup User
New Guy wrote:
> they shouldn't be able to download your whole page- just the html part.
> Hence- No functionality.
Not true. All that the attacker needs to do is to change the value of
the action attribute to the URL, and the form data will be accepted.
Using a hidden field that would permit anyone to change the SQL query
from from INSERT to DELETE is simply asking for trouble. Permission to
delete should be restricted to registered users on a password-protected
part of the site.
--
David Powers, Adobe Community Expert
Author, "Foundation PHP for Dreamweaver 8" (friends of ED)
Author, "PHP Solutions" (friends of ED)
http://foundationphp.com/
Copy link to clipboard
Copied
Copy link to clipboard
Copied