[TYPO3-dev]  Strange L-attribute parameters
    Thomas Schröder 
    thomas.schroeder at tu-ilmenau.de
       
    Wed Jul  1 00:05:56 CEST 2009
    
    
  
Hi guys,
some days befor we notice some strange parameters with the language 
attribute in generated URLs spread partial over the website. Several 
times we found something like L=1).com or 
L=http%3A%2F_domain_%2F_file_%3F. _domain_ is a valid domain and _file_ 
a txt-filename. I don't want to post the concrete values in the list.
Two years ago we had a similar problem. At that time I filtered the L 
attribute with the allowed values and cleared the page-cache several 
times a day over several weeks until everything was ok again. I also 
searched for the strings in several encodings in the database and 
sourcecode, but I couldn't find the source.
Did somebody noticed related problems? What do you suggest to solve the 
problem? Is it a security problem?
Best Regards,
	Thomas
    
    
More information about the TYPO3-dev
mailing list