Closed Bug 463069 (WH-1628756) Opened 17 years ago Closed 17 years ago

XSS vulns on tiki-browse_categories.php

Categories

(support.mozilla.org :: Knowledge Base Software, task)

task
Not set
critical

Tracking

(Not tracked)

VERIFIED FIXED

People

(Reporter: reed, Assigned: laura)

References

()

Details

(Keywords: wsec-xss, Whiteboard: tiki_bug, tiki_upstreamed)

Attachments

(1 file)

Assignee: nobody → laura
Target Milestone: --- → 0.7.2
Sadly, the fix for the first three bugs doesn't fix this one.
Group: websites-security
Group: websites-security
More to the point, the first one is fixed but the second one isn't. Not too hard to iron out I hope.
Attachment #347382 - Flags: review?(nelson)
Attachment #347382 - Flags: review?(nelson) → review+
Committed in r19632.
Status: NEW → RESOLVED
Closed: 17 years ago
Keywords: push-needed
Resolution: --- → FIXED
[1] https://support-stage.mozilla.org/tiki-browse_categories.php?find=%22%20STYLE=%22background-image:%20x%28a:whs%28%29%29&deep=off&type=&parentId=13&offset=930&sort_mode=name_asc: "Error An unexpected error has occurred!" [2] https://support-stage.mozilla.org/tiki-browse_categories.php?find=&deep=off&type=&parentId=%22%20STYLE=%22background-image:%20x%28a:whs%28%29%29&offset=930&sort_mode=name_asc: "Choose a category Top :: << <<" I couldn't ever reproduce [1], but Laura mentions that in comment 2; [2] I could reproduce on production: "Choose a category admin category Top :: Set email notifications for this category: watch this category Currently off" Verified FIXED
Status: RESOLVED → VERIFIED
Whiteboard: tiki_bug
Whiteboard: tiki_bug → tiki_bug, tiki_upstreamed
Adding keywords to bugs for metrics, no action required. Sorry about bugmail spam.
Keywords: wsec-xss
These bugs are all resolved, so I'm removing the security flag from them.
Group: websites-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: