Closed
Bug 1238912
Opened 9 years ago
Closed 9 years ago
Database Query Error on m.wiki.mozilla.org
Categories
(Websites :: wiki.mozilla.org, defect, P3)
Websites
wiki.mozilla.org
Tracking
(Not tracked)
RESOLVED
DUPLICATE
of bug 1237549
People
(Reporter: serverghosts, Unassigned)
References
()
Details
Attachments
(1 file)
|
21.65 KB,
image/png
|
Details |
User Agent: Mozilla/5.0 (Linux; U; Android 4.4.2; en-US; PrimoC4 Build/WALTON) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 UCBrowser/10.8.0.718 U3/0.8.0 Mobile Safari/534.30
Steps to reproduce:
Go here:https://m.wiki.mozilla.org/index.php?search=
My payload: --!><svg/onload=prompt(1)
Actual results:
Showing database error may lead to SQL injection
Expected results:
Nothing
| Reporter | ||
Updated•9 years ago
|
| Reporter | ||
Comment 1•9 years ago
|
||
https://m.wiki.mozilla.org/index.php?search=- this - is causing the error
OS: Android → Unspecified
Hardware: All → Unspecified
| Reporter | ||
Comment 2•9 years ago
|
||
https://m.wiki.mozilla.org/index.php?search=--%20or. Its a sqli error
| Reporter | ||
Updated•9 years ago
|
Severity: normal → critical
Priority: -- → P3
Updated•9 years ago
|
Group: core-security → websites-security
Component: Untriaged → wiki.mozilla.org
Product: Core → Websites
Summary: Database Query Error → Database Query Error on m.wiki.mozilla.org
Version: 1.0 Branch → unspecified
Updated•9 years ago
|
Status: UNCONFIRMED → RESOLVED
Closed: 9 years ago
Resolution: --- → DUPLICATE
Updated•9 years ago
|
Group: websites-security
You need to log in
before you can comment on or make changes to this bug.
Description
•