A bug in Membership product? (member password can be revealed by dtml method accessible by anonymous)
4 Jan
2001
4 Jan
'01
2:36 a.m.
Hi Bill, A dtml method with these lines: <dtml-with "acl_users.getItem('z')"> <dtml-var password> </dtml-with> will show the password, despite that the methode is accessible by anonymous. Members in my site is allowed to use dtml method. How can I prevent them from reading others' properties? Dirksen __________________________________________________ Do You Yahoo!? Yahoo! Photos - Share your holiday photos online! http://photos.yahoo.com/
9223
Age (days ago)
9223
Last active (days ago)
0 comments
1 participants
participants (1)
-
Dirksen