Hi All,

I have found what I think is quite a serious bug in Spectra 1.5.

When using the container editor in designmode the application.cfm for your 
site is bypassed in favour of the one in http://<yourdomain>/allaire/spectra/

This happens because the page which creates the designmode interface 
resides in this directory and is called via a normal http request.

I noticed this a few days ago and assumed that it was manageable, but now 
that I have progressed further I have realized that I am unable to perform 
any of the normal security checks and so on that I would normally have in 
my Application and that I can't set any request variables that I want to 
use in my handler files.

Has anyone else noticed this and found a way around it?

spike


Stephen Milligan
Internet Developer and Allaire training guru
Tel: +34 686 021171
ICQ: 15831735
Email: [EMAIL PROTECTED] <mailto:[EMAIL PROTECTED]>
"In the land of the blind, the one-eyed man is king!"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Structure your ColdFusion code with Fusebox. Get the official book at 
http://www.fusionauthority.com/bkinfo.cfm
------------------------------------------------------------------------------
To Unsubscribe visit 
http://www.houseoffusion.com/index.cfm?sidebar=lists&body=lists/spectra_talk or send a 
message to [EMAIL PROTECTED] with 'unsubscribe' in the body.

Reply via email to