Remove attachment action submitted via GET rather than POST

XMLWordPrintable

    • Type: Bug
    • Resolution: Duplicate
    • Priority: Medium
    • None
    • Affects Version/s: 2.8
    • Component/s: None

      202.47.1.18 - - [19/May/2008:01:19:00 -0500] "GET /pages/removeattachment.action?pageId=685540383&fileName=kermit.jpg&version=1 HTTP/1.1" 200 3603 ...
      

      Kiddies, do you know what happens to bad webapps that use GETs to submit "delete" operations rather than POSTs?

      In the night the Big Bad Googlebot comes along clicking every link, ignores the "Do you really want to delete?" Javascript, and deletes every attachment on the page.

            Assignee:
            Unassigned
            Reporter:
            Jeff Turner
            Votes:
            1 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved: