Next
Previous
Contents
advisory CA-2000-02has little to do with Boa. As of version 0.94.4, Boa's escaping rules have been
cleaned up a little, but they weren't that bad before. The example CGI
programs have been updated to show what effort is needed there. If you
write, maintain, or use CGI programs under Boa (or any other server) it's
worth your while to read and understand this advisory. The real problem,
however, boils down to browser and web page designers emphasizing frills
over content and security. The market leading browsers assume (incorrectly)
that all web pages are trustworthy.
Next
Previous
Contents