Joined: Mar 06, 2004 Posts: 1156 Location: Sanbornton, NH USA
Posted:
Sun Jun 19, 2005 11:03 am
Benson, have you added in scan, validation and filter fucntions to Nuke so that the editor:
A) Can't inject harmful SQL into the database
B) Can't inject harmful SQL into the database even when encoded
C) Can't execute an unauthorized action
If not, this is just as bad as having TinyMCE with 7.7 and 7.8.
There is no "Quick Fix" for a Nuke Platform. The platform was NEVER designed for any WYSIWYG Editor. Quite frankly, it is not quite ready for as, NUKE NEEDS A VALIDATION FUNCTION CREATED FOR ANY EDITOR!
Without validation functions, adding any editor is simply like taking a bath with a plugged-in toaster.
NOT a good idea.
Do a google search by any of these editors with the word validation after it and you will see 1000 examples of bug reports (mostly security vulnerability reports) about people whom have used them without validation, being hacked.
View next topic View previous topic
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum