HCL
Skip to main content  
 
   


SPRTechnote


Validating Domino Frameset Src Arguments

Technote Number: 1211961


Problem:
This enhancement request was reported to Quality Engineering and has been
addressed in Domino 6.5.4 Fix Pack 1 (6.5.4.1), Domino 6.5.5, and Domino 7.0.
Refer to the Upgrade Central site for details on upgrading Notes/Domino to
these releases.

To enable this setting, edit the notes.ini file and add the following line:

DominoValidateFramesetSRC=1

This parameter is static, so to enable it, you must edit the notes.ini manually
and restart the server for it to take effect.

With this setting enabled, when the Web Server OpenFrameSet command has a Src
argument, the argument's value is validated to ensure that it designates a
design note in the same database as the frameset being opened. This validation
prevents improper use of the Src argument to redirect browsers to arbitrary Web
sites, which is a possible security vulnerability. Note that the Src and Frame
arguments are used by the autoframe feature and are not intended for general
use.
More >





  Document options
Print this document
Print view

  Search
Search Advanced Search


  Fix list views

 RSS feeds   RSS
Subscribe to the fix list

  Resources
Using this database
View notices

  HCL Support
HCL Support


    About HCL Privacy Contact