catch invalid URLs
Bug #266445 reported by
Jidanni
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
GNU Mailman |
New
|
Medium
|
Unassigned |
Bug Description
One finds one can use URLs like
http://
and still visit the administration pages as if one typed in a correct
URL.
Somewhere in Mailman, something is not checking the URL beyond a
certain length or segment.
You might say "so what?", but if you allow these to work, soon all
kinds of people's typos will end up in documents as being the URL to
use to do various tasks, just because they happened to work that day.
(Yes, the above example does not bypass password checks.)
[http://
To post a comment you must log in.
Originator: YES
http:// www.python. org/cgi- bin/faqw- mm.py?req= show&file= faq04.057. htp is an
example of a evil looseness.