MVC Routing Security Hole(squaredroot.com)
submitted by
TroyMG(2670) 3 years, 7 months ago
Stephen Walther's latest MVC tip introduced me to the MVC framework's ability to pass server variables into actions as parameters. Unfortunately using this feature is a very bad idea and could jeopardize the security of your application. Take a look at a code sample you might find surprising.
|category: ASP.NET
|Views: 238
tags:
hacking mvc.net TroyGoode ASPNETMVC 3.5 another
Everyones tags:
Your Tags: