MMBase

Web-site visitor can pollute the logs

Details

  • Type: Bug Bug
  • Status: Open Open
  • Priority: Major Major
  • Resolution: Unresolved
  • Affects Version/s: 1.9.0
  • Fix Version/s: 2.0.0
  • Component/s: Core
  • Description:
    Hide
    A visitor of an mmbase web-site can pollute the logs by hacking in the URL.

    E.g. by changing a node-number in the URL to a node number of the wrong type:

    mitulo/ 2009-04-06 13:07:16,434 WARN mmbase.module.core.MMObjectNode checkFieldExistance.454 - Application stacktrace
            at org.mmbase.bridge.jsp.taglib.FieldTag.doStartTag(FieldTag.java:236)
            at org.apache.jsp.nazorg.thema.themes.articles.article_jsp._jspx_meth_mm_005ffield_005f28(article_jsp.java:5791)


    mitulo/ 2009-04-06 13:07:16,071 WARN mmbase.module.core.ClusterBuilder addRelationDirections.1127 - No relation defined between typedef and ima
    ges using RelationStep(tablename:descposrel, alias:descposrel, nodes:null, dir:destination, role:DescriptionPositionRelation/descposrel) with di
    rection(s) DESTINATION. Trying anyway, but perhaps the query should be fixed, because this should always result nothing.



    These are sensible warnings, but it would be good if you could easily configure them away on a production environment.
    Show
    A visitor of an mmbase web-site can pollute the logs by hacking in the URL. E.g. by changing a node-number in the URL to a node number of the wrong type: mitulo/ 2009-04-06 13:07:16,434 WARN mmbase.module.core.MMObjectNode checkFieldExistance.454 - Application stacktrace         at org.mmbase.bridge.jsp.taglib.FieldTag.doStartTag(FieldTag.java:236)         at org.apache.jsp.nazorg.thema.themes.articles.article_jsp._jspx_meth_mm_005ffield_005f28(article_jsp.java:5791) mitulo/ 2009-04-06 13:07:16,071 WARN mmbase.module.core.ClusterBuilder addRelationDirections.1127 - No relation defined between typedef and ima ges using RelationStep(tablename:descposrel, alias:descposrel, nodes:null, dir:destination, role:DescriptionPositionRelation/descposrel) with di rection(s) DESTINATION. Trying anyway, but perhaps the query should be fixed, because this should always result nothing. These are sensible warnings, but it would be good if you could easily configure them away on a production environment.

Issue Links

Activity

Michiel Meeuwissen made changes - 2009-04-06 13:20
Field Original Value New Value
Link This issue is related to (out) MMB-426 [ MMB-426 ]
Michiel Meeuwissen made changes - 2009-04-06 13:30
Fix Version/s 2.0.0 [ 10143 ]
Fix Version/s 1.9.1 [ 10170 ]

People

Dates

  • Created:
    2009-04-06 13:19
    Updated:
    2009-04-06 15:25