Friday, November 21, 2008
  
 
In This Section
Minimize
Where was I Where was I
Maximize
Ads

Learn more

Learn more

Learn more

Learn more

Learn more

Ads

See all DNNSpired.com modules on DotNetNuke® Marketplace

See all DNNSpired.com modules on Snowcovered

Users Online Users Online
Minimize
Membership Membership:
Latest New User Latest:Justin Moore
New Today New Today:9
New Yesterday New Yesterday:5
User Count Overall:1744

Roles OnlineRoles Online:
TotalSupport:0

People Online People Online:
Visitors Visitors:5
Members Members:0
Total Total:5

PageOptions PageOptions
Print current page.  Print This Page
Email current page.  Email This Page
  Bookmark
Sets or adds current page to Homepage(s).  Homepage

     
  Wish List View Cart  

Inspired to extend DotNetNuke®, everyday.

Login
Register
 
 English (United States)  Français (Canada) Italiano (Italia)  Español (España)
 
  Forums Forums     Contact Us Contact Us     Help Help  
DNNSpired Forums
 
  Forums  Autosize Iframe  Discuss It, Lea...  Security Issue
Previous Previous
 
Next Next
New Post 8/20/2008 10:45 AM
Unresolved
User is offline Speedster
2 posts
No Ranking


Security Issue  (United Kingdom)

Hi,

 

Our security scan showed that if you enter the following

 

http://....../default.aspx?au_iframe=www.microsoft.com

 

you will get through to the microsoft website through the ds_autosize iFrame, is there anyway of controling what urls are allowed through the querystring?

 

Thanks

 
New Post 8/20/2008 11:44 AM
User is offline David Dyer
18 posts
No Ranking


Re: Security Issue  (United States)

Currently this not avaliable.  You can disable the feature in the configuration of the module, to prevent the iframe from using the query string feature.

 
New Post 8/21/2008 11:22 AM
User is offline Speedster
2 posts
No Ranking


Re: Security Issue  (United Kingdom)

Hi,

 

We need the feature to enter URLs but we wouldn't want other people to edit the URL property. Are there any plans on improving this security issue?

Thanks

 
Previous Previous
 
Next Next
  Forums  Autosize Iframe  Discuss It, Lea...  Security Issue
Social Bookmarks Social Bookmarks
Add this link to my Digg It account.  Digg This
Add this link to my del.ico.us account  del.ico.us
Add this link to my Slashdot account  Slashdot
Add this link to my Yahoo account  Y! MyWeb
Add this link to Newsvine account  Newsvine
Add this link to my Reddit account  Reddit

  Forums Forums     Contact Us Contact Us     Help Help  
About Us | Products | Support | Purchase | Downloads DotNetNuke® Bronze Sponsor
  Page Ranking Tool