Wow. Very detailed response Charlie and with lots of useful information!
 
I hadn't had a chance to get to back to this until now as a few other 
projects got in the way of playing :)  I hadn't realised it was unrelated 
to cflocation, Thank you for that as it does make it easier to test.  I 
guess I got fixated with cflocation as I'm having other issues with it 
since moving to CF10 (e.g. scheduled task won't always follow the 
cflocation).
 
One other strange thing I did notice with cfform was when passing something 
like form=new in the query string (without an action) is fine but not the 
other way around.  If you pass new=form, or even new1, new2 etc. the whole 
lot is removed.  I guess this relates to XSS that you mentioned, as I can 
imagine new being treated as a suspect statement.
 
I'm going to do some more testing and then log a bug....not that any of my 
stuff ever gets fixed/added (e.g. NTLM support) but I'll do it anyway.  
Can't complain about Adobe not fixing problems if they aren't logged :)
 
Thank you again for the detailed response Charlie, looks like I have some 
more reading to do today.
 
Have a great weekend.
 
Cheers
Mark

-- 
You received this message because you are subscribed to the Google Groups 
"cfaussie" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to cfaussie+unsubscr...@googlegroups.com.
To post to this group, send email to cfaussie@googlegroups.com.
Visit this group at http://groups.google.com/group/cfaussie.
For more options, visit https://groups.google.com/groups/opt_out.

Reply via email to