foundeo
searchimplicitscopes=FALSE and if a variable name is not prefixed with a scope identifier, an error is returned._β - I wrote up a blog entry with some info here: https://www.petefreitag.com/blog/cf-searchimplicitscopes/ but really this is quite a major change, and will require extensive testing for mostquetwo
03/12/2024, 7:21 PMbdw429s
03/12/2024, 7:22 PMbdw429s
03/12/2024, 7:22 PMbdw429s
03/12/2024, 7:22 PMJames Harris
03/12/2024, 7:26 PMJames Harris
03/12/2024, 7:26 PMGenerally, a referenced variable is searched in various scopes before a match is found. In cases where a variable is not found in common scopes like function, local scope, and variable scopes, the search continues in implicit scopes, which can take a while. Implicit scope search can be disabled by using a new application setting called searchImplicitScopes in Application.cfc. It accepts a boolean value.bdw429s
03/12/2024, 7:26 PMbdw429s
03/12/2024, 7:27 PMbdw429s
03/12/2024, 7:27 PMbdw429s
03/12/2024, 7:29 PMJames Harris
03/12/2024, 7:31 PMquetwo
03/12/2024, 7:31 PMJames Harris
03/12/2024, 7:32 PMChad Norris
03/12/2024, 7:33 PMChad Norris
03/12/2024, 7:34 PMBrian Reilly
03/12/2024, 7:35 PMbdw429s
03/12/2024, 7:36 PMevaluate() for crying out loud, with just a note saying, "Hey idiots, don't pass random stuff into this". The same sort of general warning always applied to unscoped variables IMO.bdw429s
03/12/2024, 7:37 PMBrian Reilly
03/12/2024, 7:37 PM<iframe> in a <cfdocument>bdw429s
03/12/2024, 7:39 PMbdw429s
03/12/2024, 7:39 PMquetwo
03/12/2024, 7:40 PMbdw429s
03/12/2024, 7:40 PMurl would allow you to "inject" it basically. That was just bad code on our part and we fixed it.bdw429s
03/12/2024, 7:41 PMbdw429s
03/12/2024, 7:41 PMfoundeo
foundeo
<cfdocument>Hi #name#</cfdocument> with doc.cfm?name=<iframe src=file:///etc which I feel is a well known issuefoundeo
cfexecute tag_βbdw429s
03/12/2024, 7:55 PM<cfset variables.name = url.name>
<cfdocument>Hi #name#</cfdocument>bdw429s
03/12/2024, 7:55 PMBrian Reilly
03/12/2024, 7:56 PMbdw429s
03/12/2024, 7:57 PMbdw429s
03/12/2024, 7:58 PMbdw429s
03/12/2024, 7:59 PMbdw429s
03/12/2024, 7:59 PMBrian Reilly
03/12/2024, 8:01 PMfoundeo
bdw429s
03/12/2024, 8:08 PMBrian Reilly
03/12/2024, 8:12 PMBrian Reilly
03/12/2024, 8:14 PMbdw429s
03/12/2024, 8:26 PMbdw429s
03/12/2024, 8:27 PMBrian Reilly
03/12/2024, 8:27 PMdavequested
03/12/2024, 8:33 PMbdw429s
03/12/2024, 8:33 PMbdw429s
03/12/2024, 8:33 PMbdw429s
03/12/2024, 8:33 PMdavequested
03/12/2024, 8:35 PMbdw429s
03/12/2024, 8:36 PMdavequested
03/12/2024, 8:36 PMBrian Reilly
03/12/2024, 8:36 PMdavequested
03/12/2024, 8:40 PMDave Merrill
03/12/2024, 8:51 PMSid Wing
03/12/2024, 8:52 PMDave Merrill
03/12/2024, 8:52 PMSid Wing
03/12/2024, 8:52 PMDave Merrill
03/12/2024, 8:54 PMSid Wing
03/12/2024, 8:56 PMDave Merrill
03/12/2024, 9:02 PMSid Wing
03/12/2024, 9:03 PMDave Merrill
03/12/2024, 9:03 PMdavequested
03/12/2024, 9:04 PMDave Merrill
03/12/2024, 9:15 PMdavequested
03/12/2024, 9:16 PMDave Merrill
03/12/2024, 9:21 PMDave Merrill
03/12/2024, 9:22 PMfoundeo
Dave Merrill
03/12/2024, 9:25 PMdavequested
03/12/2024, 9:48 PMRochelle Hannah
03/13/2024, 3:29 AMSatyam Mishra
03/13/2024, 9:44 AMBrian Reilly
03/13/2024, 2:36 PMBrian Reilly
03/13/2024, 2:45 PM<cfdocument> has been / should still be considered a potentially-dangerous function if it handles user-controlled input, so all user-controlled input into it should be strictly validated (cf. https://foundeo.com/security/guide/server-side-request-forgery/ @foundeo)James Harris
03/13/2024, 8:17 PMMark Takata (Adobe)
03/13/2024, 10:15 PM