Last Msg First Msg
























method org.apache.roller.weblogger.webservices. adminprotocol.BasicAuthenticator__static_init










method void org.apache.roller.weblogger.webservices. adminprotocol.BasicAuthenticator(HttpServletRequest )
postthis.request == req
postinit'ed(this.request)
postinit'ed(this.roller)
unanalyzedcall on org.apache.roller.weblogger.business. WebloggerFactory:getWeblogger










method void authenticate()
prethis.request != null
pre(soft) this.roller != null
presumptionjava.lang.String:indexOf(...)@47 <= 232-2
presumptionjavax.servlet.http.HttpServletRequest:getHeader(... )@36 != null
postinit'ed(java.lang.String:substring(...)._tainted)
postthis.userName == One-of{null, &java.lang. String:substring(...)}
unanalyzedcall on getUserData
unanalyzedcall on org.apache.roller.weblogger.pojos. User:getPassword
unanalyzedcall on org.apache.roller.weblogger.config. WebloggerConfig:getProperty
unanalyzedcall on java.lang.Boolean:valueOf
unanalyzedcall on java.lang.Boolean:booleanValue
unanalyzedcall on org.apache.roller.weblogger.util. Utilities:encodePassword
unanalyzedcall on java.lang.String:trim
unanalyzedcall on org.apache.roller.weblogger.pojos. User:getUserName
unanalyzedcall on java.lang.String:equals
unanalyzedcall on org.apache.roller.weblogger.webservices. adminprotocol.HandlerException
unanalyzedcall on java.lang.Exception
unanalyzedcall on org.apache.roller.weblogger.pojos. User:hasRole
unanalyzedcall on org.apache.roller.weblogger.pojos. User:getEnabled
unanalyzedcall on org.apache.roller.weblogger.business. Weblogger:getUserManager
unanalyzedcall on org.apache.roller.weblogger.business. UserManager:getUserByUserName
unanalyzedcall on java.lang.Throwable:__curr_excep_obj
test_vectorjava.lang.String:equalsIgnoreCase(...)@44: {0}, {1}
test_vectorjava.lang.String:indexOf(...)@47: {-1}, {-231..-2, 0..232-2}
test_vectorjava.util.StringTokenizer:hasMoreTokens(...)@42: {0}, {1}









  infomethod not available-- call on byte[] org.apache.commons.codec.binary. Base64:decodeBase64(byte[])










Prev Msg Next Msg
+
low
conditional throwcheck might fail: requires getUserName(...) != null
Prev Msg Next Msg