[Nagios-devel] Invalid cgi DOM patch
Posted: Fri Dec 17, 2010 10:54 am
--0-1541669368-1292581633=:86679
Content-Type: multipart/alternative; boundary="0-678407556-1292581633=:86679"
--0-678407556-1292581633=:86679
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: quoted-printable
Hi list,=0A=0Aattached is a small path for an inconsistency=0Ain some of th=
e CGI's DOM. Typical example:=0A=0A...=0A=0Ais not valid. Instead it should be:=0A=0A...=0Aor=0A...=0A=0AWhen loaded in its own window, frame or iframe all=0Ashow=
s up ok. However, when loaded in an existing=0ADOM, typically in a -ta=
g, some forms are lost=0Ain some browsers (observed in FF3.x).=0A=0AThe pat=
ch is against release 3.2.3 and has been=0Atested in Chrome3, Chrome8, FF3.=
5, IE6, IE8 and=0AOpera10.=0A=0AAffected CGIs are:=0A - avail.cgi=0A - conf=
ig.cgi=0A - histogram.cgi=0A - trends.cgi=0A=0AThere are probably more bugs=
in there, but this=0Awas my immediate itch. Please include or comment.=0A=
=0AThanks in adv=0A/S-G=0A______________________________________________=0A=
=0ASven-G=F6ran Bergh, Systemasis AB=0A=0A_________________________________=
_____________=0A=0A=0A
--0-678407556-1292581633=:86679
Content-Type: text/html; charset=iso-8859-1
Content-Transfer-Encoding: quoted-printable
Hi list,attached is a small =
path for an inconsistencyin some of the CGI's DOM. Typical example:=
<table><form><tr><td>...</td></tr>&=
lt;/form></table>is not valid. Instead it should be:<form><table><tr><td>...</td></tr><=
;/table></form>or<table><tr><td><form=
>...</form></td></tr></table>When loaded=
in its own window, frame or iframe allshows up ok. However, when loade=
d in an existingDOM, typically in a <div>-tag, some forms are los=
tin some browsers (observed in FF3.x).The patch is against rele=
ase 3.2.3 and has beentested in Chrome3, Chrome8, FF3.5, IE6, IE8
andOpera10.Affected CGIs are: - avail.cgi - =
config.cgi - histogram.cgi - trends.cgiThere are =
probably more bugs in there, but thiswas my immediate itch. Please incl=
ude or comment.Thanks in adv/S-G___________________________=
___________________Sven-G=F6ran Bergh, Systemasis AB______=
________________________________________=0A
--0-678407556-1292581633=:86679--
--0-1541669368-1292581633=:86679
Content-Type: application/octet-stream; name="nagios-3.2.3_cgi-DOM.patch"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="nagios-3.2.3_cgi-DOM.patch"
ZGlmZiAtdXIgbmFnaW9zLTMuMi4zL2NnaS9hdmFpbC5jIG5hZ2lvcy0zLjIu
My1uZXcvY2dpL2F2YWlsLmMKLS0tIG5hZ2lvcy0zLjIuMy9jZ2kvYXZhaWwu
YwkyMDEwLTA4LTA2IDAyOjUwOjQ5LjAwMDAwMDAwMCArMDIwMAorKysgbmFn
aW9zLTMuMi4zLW5ldy9jZ2kvYXZhaWwuYwkyMDEwLTEyLTE3IDEwOjM1OjM2
LjAwMDAwMDAwMCArMDEwMApAQCAtNDk3LDExICs0OTcsMTQgQEAKIAkJLyog
cmlnaHQgaGFuZCBjb2x1bW4gb2YgdG9wIHJvdyAqLwogCQlwcmludGYoIjx0
ZCBhbGlnbj1yaWdodCB2YWxpZ249Ym90dG9tIHdpZHRoPTMzJSU+XG4iKTsK
IAorCQlwcmludGYoIjxmb3JtIG1ldGhvZD1cIkdFVFwiIGFjdGlvbj1cIiVz
XCI+XG4iLEFWQUlMX0NHSSk7CiAJCXByaW50ZigiPHRhYmxlIGJvcmRlcj0w
IENMQVNTPSdvcHRCb3gnPlxuIik7CiAKIAkJaWYoZGlzcGxheV90eXBlIT1E
SVNQTEFZX05PX0FWQUlMICYmIGdldF9kYXRlX3BhcnRzPT1GQUxTRSl7CiAK
LQkJCXByaW50ZigiPGZvcm0gbWV0aG9kPVwiR0VUXCIgYWN0aW9uPVwiJXNc
Ij5cbiIsQVZBSUxfQ0dJKTsKKwkJCXByaW50ZigiPHRyPjx0ZCB2YWxpZ249
dG9wIGFsaWduPWxlZnQgY2xhc3M9J29wdEJveEl0ZW0nPkZpcnN0IGFzc3Vt
ZWQgJXMgc3RhdGU6PC90ZD48dGQgdmFsaWduPXRvcCBhbGlnbj1sZWZ0IGNs
YXNzPSdvcHRCb3hJdGVtJz4lczwvdGQ+PC90cj5cbiIsKGRpc3BsYXlfdHlw
ZT09RElTUExBWV9TRVJWSUNFX0FW
...[email truncated]...
This post was automatically imported from historical nagios-devel mailing list archives
Original poster: [email protected]
Content-Type: multipart/alternative; boundary="0-678407556-1292581633=:86679"
--0-678407556-1292581633=:86679
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: quoted-printable
Hi list,=0A=0Aattached is a small path for an inconsistency=0Ain some of th=
e CGI's DOM. Typical example:=0A=0A...=0A=0Ais not valid. Instead it should be:=0A=0A...=0Aor=0A...=0A=0AWhen loaded in its own window, frame or iframe all=0Ashow=
s up ok. However, when loaded in an existing=0ADOM, typically in a -ta=
g, some forms are lost=0Ain some browsers (observed in FF3.x).=0A=0AThe pat=
ch is against release 3.2.3 and has been=0Atested in Chrome3, Chrome8, FF3.=
5, IE6, IE8 and=0AOpera10.=0A=0AAffected CGIs are:=0A - avail.cgi=0A - conf=
ig.cgi=0A - histogram.cgi=0A - trends.cgi=0A=0AThere are probably more bugs=
in there, but this=0Awas my immediate itch. Please include or comment.=0A=
=0AThanks in adv=0A/S-G=0A______________________________________________=0A=
=0ASven-G=F6ran Bergh, Systemasis AB=0A=0A_________________________________=
_____________=0A=0A=0A
--0-678407556-1292581633=:86679
Content-Type: text/html; charset=iso-8859-1
Content-Transfer-Encoding: quoted-printable
Hi list,attached is a small =
path for an inconsistencyin some of the CGI's DOM. Typical example:=
<table><form><tr><td>...</td></tr>&=
lt;/form></table>is not valid. Instead it should be:<form><table><tr><td>...</td></tr><=
;/table></form>or<table><tr><td><form=
>...</form></td></tr></table>When loaded=
in its own window, frame or iframe allshows up ok. However, when loade=
d in an existingDOM, typically in a <div>-tag, some forms are los=
tin some browsers (observed in FF3.x).The patch is against rele=
ase 3.2.3 and has beentested in Chrome3, Chrome8, FF3.5, IE6, IE8
andOpera10.Affected CGIs are: - avail.cgi - =
config.cgi - histogram.cgi - trends.cgiThere are =
probably more bugs in there, but thiswas my immediate itch. Please incl=
ude or comment.Thanks in adv/S-G___________________________=
___________________Sven-G=F6ran Bergh, Systemasis AB______=
________________________________________=0A
--0-678407556-1292581633=:86679--
--0-1541669368-1292581633=:86679
Content-Type: application/octet-stream; name="nagios-3.2.3_cgi-DOM.patch"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="nagios-3.2.3_cgi-DOM.patch"
ZGlmZiAtdXIgbmFnaW9zLTMuMi4zL2NnaS9hdmFpbC5jIG5hZ2lvcy0zLjIu
My1uZXcvY2dpL2F2YWlsLmMKLS0tIG5hZ2lvcy0zLjIuMy9jZ2kvYXZhaWwu
YwkyMDEwLTA4LTA2IDAyOjUwOjQ5LjAwMDAwMDAwMCArMDIwMAorKysgbmFn
aW9zLTMuMi4zLW5ldy9jZ2kvYXZhaWwuYwkyMDEwLTEyLTE3IDEwOjM1OjM2
LjAwMDAwMDAwMCArMDEwMApAQCAtNDk3LDExICs0OTcsMTQgQEAKIAkJLyog
cmlnaHQgaGFuZCBjb2x1bW4gb2YgdG9wIHJvdyAqLwogCQlwcmludGYoIjx0
ZCBhbGlnbj1yaWdodCB2YWxpZ249Ym90dG9tIHdpZHRoPTMzJSU+XG4iKTsK
IAorCQlwcmludGYoIjxmb3JtIG1ldGhvZD1cIkdFVFwiIGFjdGlvbj1cIiVz
XCI+XG4iLEFWQUlMX0NHSSk7CiAJCXByaW50ZigiPHRhYmxlIGJvcmRlcj0w
IENMQVNTPSdvcHRCb3gnPlxuIik7CiAKIAkJaWYoZGlzcGxheV90eXBlIT1E
SVNQTEFZX05PX0FWQUlMICYmIGdldF9kYXRlX3BhcnRzPT1GQUxTRSl7CiAK
LQkJCXByaW50ZigiPGZvcm0gbWV0aG9kPVwiR0VUXCIgYWN0aW9uPVwiJXNc
Ij5cbiIsQVZBSUxfQ0dJKTsKKwkJCXByaW50ZigiPHRyPjx0ZCB2YWxpZ249
dG9wIGFsaWduPWxlZnQgY2xhc3M9J29wdEJveEl0ZW0nPkZpcnN0IGFzc3Vt
ZWQgJXMgc3RhdGU6PC90ZD48dGQgdmFsaWduPXRvcCBhbGlnbj1sZWZ0IGNs
YXNzPSdvcHRCb3hJdGVtJz4lczwvdGQ+PC90cj5cbiIsKGRpc3BsYXlfdHlw
ZT09RElTUExBWV9TRVJWSUNFX0FW
...[email truncated]...
This post was automatically imported from historical nagios-devel mailing list archives
Original poster: [email protected]