Odd behavior – any security risks?
-
I found that when I have a link to my blog, e.g.:
https://www.example.com/blog/?https://some-other-site.com
anything after the question mark is accepted and will lead to the blog’s front page. In fact, it appears that any link of the form:
https://example.com/blog/?p=1234?anything-at-all
the text after the final question mark is ignored, and the link simply brings you to the page referred to by p=1234.
I find this behavior puzzling and mildly unsettling. It looks like it’s a bug that silently tries to “do the right thing” and ignore meaningless text, if the first part of the link is OK. Is that a good idea?
Second, I found several such links in my log files, where the part after the question mark pointed to another Website.
Does anyone have any insight into this, and should I be concerned? Thanks.
- The topic ‘Odd behavior – any security risks?’ is closed to new replies.