Skip to content

Adds test for SSI query string injection#591

Closed
ichristod wants to merge 1 commit into
apache:trunkfrom
ichristod:test-ssi-query-string-injection
Closed

Adds test for SSI query string injection#591
ichristod wants to merge 1 commit into
apache:trunkfrom
ichristod:test-ssi-query-string-injection

Conversation

@ichristod
Copy link
Copy Markdown

This change adds a regression test to the pyhttpd test suite to ensure that Server Side Includes cannot inject query string to #exec cmd=..., as described here.

IMHO the nature of the SSI wouldn't require a new folder structure for mod_include, thats why I used core module. If you think is not a good approach I can create inside pyhttpd a new folder structure with the relevant classes and configurations for the mod_include.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant