[ic] IC-specific hacking attempt

Kevin Walsh kevin at cursor.biz
Sun Mar 28 17:02:24 EST 2004


Doug Alcorn [lathinet at yahoo.com] wrote:
> I applied the patch and it half-way works.  It
> prevents the interpreting of the variable in the main
> body; however, the page still has the interpreted
> variable in the page title.
> 
You are probably using @@MV_PREV_PAGE@@ instead of [subject] in
parts of your missing.html.  Either correct it to use [subject] or
upgrade to a version of Interchange that will trap attempts to exploit
the problems.  I suggest doing both.

@@MV_PREV_PAGE@@ was patched some time ago.  A new version to cover
[subject] will be released soon.  It was about to be released anyway.

-- 
   _/   _/  _/_/_/_/  _/    _/  _/_/_/  _/    _/
  _/_/_/   _/_/      _/    _/    _/    _/_/  _/   K e v i n   W a l s h
 _/ _/    _/          _/ _/     _/    _/  _/_/    kevin at cursor.biz
_/   _/  _/_/_/_/      _/    _/_/_/  _/    _/



More information about the interchange-users mailing list