Re: Security bug in pyblosxom (reading of arbitrary directories)
will guaraldi <[email protected]>
| Newsgroups | gmane.comp.web.pyblosxom.devel |
|---|---|
| Message-ID | <[email protected]> |
I'm unable to reproduce the issue you're seeing. All I get is "The page you are looking at is unavailable". What version of PyBlosxom are you using? What version of Python are you using? What's your datadir property set to? /will On Sat, 11 Feb 2006, FX wrote: > > Hi, > > Requesting http://site/cgi-bin/pyblosxom.cgi//etc/ will cause /etc to be > parsed as datadir and anyone with a webbrowser sees /etc/ files as blog > entries. Why? Here it is: > > pyblosxom.py:1040 > absolute_path = os.path.join(config["datadir"], path_info) > > When checking the python docs, it says for os.path.join: Joins one or more > path components intelligently. If any component is an absolute path, all > previous components are thrown away, and joining continues. > > So, what does that mean to our absolute_path? The config["datadir"] part goes > where the documentation says it will: into the bitbucket, since path_info is > an absolute path. > > I'm not a Python coder, so I leave the fix up to the developers. > > cheers > FX ------------------------------------------------------- This SF.net email is sponsored by: Splunk Inc. Do you grep through log files for problems? Stop! Download the new AJAX search engine that makes searching your log files as easy as surfing the web. DOWNLOAD SPLUNK! http://sel.as-us.falkag.net/sel?cmd=lnk&kid=103432&bid=230486&dat=121642