Taint problem with DBIx::ContextualFetch

[prev] [thread] [next] [Date index for 2004/09/09]

From: Jesse Sheidlower
Subject: Taint problem with DBIx::ContextualFetch
Date: 14:49 on 09 Sep 2004
I just ran into an odd error in a Maypole application, and was 
hoping someone could point me in the right direction, as I'm
not even sure where to start.

When logging out of an application--a task that does not involve
getting any specific input from a user--I get a 500 error with
the following in the logs:

[Thu Sep 9 10:42:50 2004] [error] Insecure dependency in
parameter 2 of
DBIx::ContextualFetch::st=HASH(0xd0432c0)->bind_param method
call while running with -T switch at
/usr/local/lib/perl5/site_perl/5.8.5/Apache/Session/Store/DBI.pm
line 113.\n

I'm getting a bit lost in these modules, the guts of which I've
never really seen, and as mentioned I'm not actually passing
any user input to this, at least not deliberately.

Thanks.

Jesse Sheidlower

Taint problem with DBIx::ContextualFetch
Jesse Sheidlower 14:49 on 09 Sep 2004

Re: Taint problem with DBIx::ContextualFetch
Tony Bowden 16:06 on 09 Sep 2004

Re: Taint problem with DBIx::ContextualFetch
Jesse Sheidlower 16:13 on 09 Sep 2004

Generated at 11:34 on 01 Dec 2004 by mariachi v0.52