<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.2" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: WebWork 2.2.6 released (Security Fix)</title>
	<link>http://jaybose.com/archives/webwork-226-released-security-fix/</link>
	<description>Yapping about stuff.</description>
	<pubDate>Fri, 10 Sep 2010 19:30:14 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.2</generator>

	<item>
		<title>By: Jay</title>
		<link>http://jaybose.com/archives/webwork-226-released-security-fix/#comment-3286</link>
		<author>Jay</author>
		<pubDate>Wed, 25 Jul 2007 20:44:18 +0000</pubDate>
		<guid>http://jaybose.com/archives/webwork-226-released-security-fix/#comment-3286</guid>
		<description>You might be right. 

I don't know if it's necessarily the responsibility of the MVC to decide what is safe or unsafe. I guess the same goes for SQL injection: should the MVC parse out safe or unsafe SQL calls in the URL?</description>
		<content:encoded><![CDATA[<p>You might be right. </p>
<p>I don&#8217;t know if it&#8217;s necessarily the responsibility of the MVC to decide what is safe or unsafe. I guess the same goes for SQL injection: should the MVC parse out safe or unsafe SQL calls in the URL?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: xrellix</title>
		<link>http://jaybose.com/archives/webwork-226-released-security-fix/#comment-3284</link>
		<author>xrellix</author>
		<pubDate>Wed, 25 Jul 2007 18:02:31 +0000</pubDate>
		<guid>http://jaybose.com/archives/webwork-226-released-security-fix/#comment-3284</guid>
		<description>Evaluating user input as an OGNL expression !!! 
Craziest thing i ever heard/seen (ok maybe not, just like a mini-mall video ranks about the same).

Why is it an XWork problem?  Wouldn't it be WW2 that parses the HTML form and requests XWork to evaluate?</description>
		<content:encoded><![CDATA[<p>Evaluating user input as an OGNL expression !!!<br />
Craziest thing i ever heard/seen (ok maybe not, just like a mini-mall video ranks about the same).</p>
<p>Why is it an XWork problem?  Wouldn&#8217;t it be WW2 that parses the HTML form and requests XWork to evaluate?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
