Re: Older versions' cancel tag and security

2007-09-25 Thread Laurie Harper
Tehmina Beg wrote: Hi, in the older versions 1.0 - 1.2.8 (i think), there was a security issue with the cancel key request parameter being able to be spoofed. You're correct, the fix for this went into 1.2.9 [1]. For details of the problem and its impact, see the original bug report [2] and th

Older versions' cancel tag and security

2007-09-24 Thread Tehmina Beg
Hi, in the older versions 1.0 - 1.2.8 (i think), there was a security issue with the cancel key request parameter being able to be spoofed. I'm not sure I understand how this works, so please correct me if i'm wrong. Say you have a page with a single field and submit, if you set the cancel request