Date: 2014-10-31 12:35 am (UTC)
Yeah, as a guy who puts together Drupal sites, this has been a shockingly bad fuckup somewhere. No one noticed that it was a problem - this has been in the code since 7.0 and it's now 7.32 - and then when it was announced it may not have quite been announced as strongly as it could have been, because I didn't realize at first that scrubbing the array indexes on this one line was that important.

And I'm really glad I never got around to updating my personal sites from Drupal 6.x yet, because they aren't vulnerable to this attack.
This account has disabled anonymous posting.
(will be screened if not validated)
If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

If you are unable to use this captcha for any reason, please contact us by email at support@dreamwidth.org

Most Popular Tags

Style Credit

Page generated 2025-06-13 01:24 pm
Powered by Dreamwidth Studios