Manuel Arostegui Ramirez wrote, On 15/01/07 16:06:
>> RewriteCond %{QUERY_STRING} (\"|%22).*(\>|%3E|<|%3C).* [NC]
>
> The question is...have you tried on your cherokee site? Is it
> vulnerable?
Yeah, it "is".
Well, actually, Cherokee has nothing to do with the vulnerability,
it's sNews work to check it's incoming data.
Cherokee takes care of the request (because it has to work with it),
but it doesn't perform any kind of test over the query string, it
goes straight to the PHP interpreter. That's the expected behaviour.
--
Greetings, alo.
_______________________________________________
Cherokee mailing list
[email protected]
http://cherokee-project.com/cgi-bin/mailman/listinfo/cherokee