[tor-bugs] #10690 [Trac]: Trac error on password change
Tor Bug Tracker & Wiki
blackhole at torproject.org
Tue Jan 21 21:09:45 UTC 2014
#10690: Trac error on password change
-------------------------+-------------------------------------------------
Reporter: GITNE | Owner: erinn
Type: defect | Status: new
Priority: | Milestone:
critical | Version:
Component: Trac | Keywords: trac password change SQL error
Resolution: | python security
Actual Points: | Parent ID:
Points: |
-------------------------+-------------------------------------------------
Comment (by nickm):
In http://trac.edgewall.org/browser/trunk/trac/web/auth.py#L231 , the
query does indeed look like it's using a proper escaping mechanism,
assuming that the underlying Python DB module is working. More
investigation is warranted.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10690#comment:2>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
More information about the tor-bugs
mailing list