angler-fishThe Vulnerability History Project

Prevent CSRF attacks against the balancer-manager (CVE-2007-6420)

      * modules/proxy/mod_proxy_balancer.c (balancer_init): New function.
  (balancer_handler): Place a nonce in the form output, and check that
  the submitted form data includes that nonce.
  (ap_proxy_balancer_register_hook): Register the new post_config hook.


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@661666 13f79535-47bb-0310-9956-ffa450edef68
    
commit 4a375eff2269d4a6178997a91c22116b3df5c272
-4
-39
expand_less