[TYPO3-dev] Strange L-attribute parameters

Thomas Schröder thomas.schroeder at tu-ilmenau.de
Wed Jul 1 00:05:56 CEST 2009


Hi guys,

some days befor we notice some strange parameters with the language 
attribute in generated URLs spread partial over the website. Several 
times we found something like L=1).com or 
L=http%3A%2F_domain_%2F_file_%3F. _domain_ is a valid domain and _file_ 
a txt-filename. I don't want to post the concrete values in the list.

Two years ago we had a similar problem. At that time I filtered the L 
attribute with the allowed values and cleared the page-cache several 
times a day over several weeks until everything was ok again. I also 
searched for the strings in several encodings in the database and 
sourcecode, but I couldn't find the source.

Did somebody noticed related problems? What do you suggest to solve the 
problem? Is it a security problem?


Best Regards,
	Thomas




More information about the TYPO3-dev mailing list