Advertisement

07.25.2008 at 08:53AM PDT, ID: 23595871
[x]
Attachment Details

php code security issue

Asked by netplus21 in Security Issues in Programming, WebApplications

Tags: pho, firefox

Hello

I have installed a script that allows users to rate articles with stars. However the background color of the stars is white instead of the background color of the page and I couldn't find where to change it from the script's admin menu.  I emailed support and they told me that the background color was transparent and that was why it couldn't be set, it would automatically be the color of the page. They asked to see a URL of where the script was working.

When I checked the html (below) I saw the URL of the scriptdevelopers in the code.

Since there are such variables as 'allowScriptAccess' and 'sameDomain' could there be any security issues with me sending them the URL?

thanks for your helpStart Free Trial
1:
2:
3:
4:
5:
6:
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0" width="145" height="40" id="starspoll" align="middle">
    <param name="allowScriptAccess" value="sameDomain" />
    <param name="movie" value="http://www.mydomain.com/starsrate.swf?id=1&owner=scriptdevelopers.com&phpURL=www.mydomain.com/&subid=" />
    <param name="quality" value="high" />
    <embed src="http://www.mydomain.com/starsrate.swf?id=1&owner=scriptdevelopers.com&phpURL=www.mydomain.com/&subid=" quality="high" width="145" height="40" name="starspoll" align="middle" allowScriptAccess="sameDomain" type="application/x-shockwave-flash" pluginspage="http://www.macromedia.com/go/getflashplayer" />
    </object>
[+][-]07.25.2008 at 10:28PM PDT, ID: 22093831

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Security Issues in Programming, WebApplications
Tags: pho, firefox
Sign Up Now!
Solution Provided By: jason1178
Participating Experts: 1
Solution Grade: B
 
 
[+][-]07.26.2008 at 10:51AM PDT, ID: 22095690

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.29.2008 at 05:43AM PDT, ID: 22110829

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.29.2008 at 10:45AM PDT, ID: 22113778

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.29.2008 at 10:46AM PDT, ID: 22113780

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628