Closed
Bug 468623
(WH-1659711)
Opened 17 years ago
Closed 16 years ago
XSS vulns on tiki-view_forum_thread.php
Categories
(support.mozilla.org :: Knowledge Base Software, task)
support.mozilla.org
Knowledge Base Software
Tracking
(Not tracked)
VERIFIED
FIXED
1.5
People
(Reporter: reed, Assigned: jsocol)
References
()
Details
(Keywords: wsec-xss, Whiteboard: tiki_test)
Attachments
(2 files)
|
7.11 KB,
patch
|
laura
:
review+
|
Details | Diff | Splinter Review |
|
27.59 KB,
patch
|
ecooper
:
review+
|
Details | Diff | Splinter Review |
http://support.mozilla.com/tiki-view_forum_thread.php?locale=en-US&forumId=3&comments_threshold=0&comments_reply_threadId=200202&comments_offset=0&thread_sort_mode=commentDate_asc&comments_per_page=20&comments_grandParentId=%22%20STYLE=%22background-image:%20x(a:whs())&comments_parentId=198544&thread_style=commentStyle_plain&post_reply=1
http://support.mozilla.com/tiki-view_forum_thread.php?locale=en-US&forumId=3&comments_threshold=0&comments_reply_threadId=198623&comments_offset=0&thread_sort_mode=commentDate_asc&comments_per_page=20&comments_grandParentId=%22%20STYLE=%22background-image:%20x(a:whs())&comments_parentId=198281&thread_style=commentStyle_plain&post_reply=1
http://support.mozilla.com/tiki-view_forum_thread.php?locale=en-US&forumId=3&comments_threshold=%22%20STYLE=%22background-image:%20x(a:whs())&comments_reply_threadId=200202&comments_offset=0&thread_sort_mode=commentDate_asc&comments_per_page=20&comments_grandParentId=198544&comments_parentId=198544&thread_style=commentStyle_plain&post_reply=1
http://support.mozilla.com/tiki-view_forum_thread.php?locale=en-US&forumId=3&comments_threshold=%22%20STYLE=%22background-image:%20x(a:whs())&comments_reply_threadId=198623&comments_offset=0&thread_sort_mode=commentDate_asc&comments_per_page=20&comments_grandParentId=198281&comments_parentId=198281&thread_style=commentStyle_plain&post_reply=1
Updated•17 years ago
|
Target Milestone: --- → 0.8.1
Updated•17 years ago
|
Assignee: nobody → smirkingsisyphus
Comment 1•17 years ago
|
||
Escaped post footer and admin action links
Attachment #356873 -
Flags: review?(laura)
Updated•17 years ago
|
Attachment #356873 -
Flags: review?(laura) → review+
Comment 2•17 years ago
|
||
Status: NEW → RESOLVED
Closed: 17 years ago
Resolution: --- → FIXED
| Reporter | ||
Comment 4•17 years ago
|
||
'comments_threshold' param
http://support.mozilla.com/tiki-view_forum_thread.php?locale=en-US&forumId=1&comments_threshold=%22whscheck=%22whscheck()&comments_parentId=2046&comments_offset=20&comments_per_page=20&thread_style=commentStyle_plain
Status: VERIFIED → REOPENED
Resolution: FIXED → ---
Target Milestone: 0.8.1 → 1.0
| Reporter | ||
Comment 5•17 years ago
|
||
<div class="mini">
<a class="prevnext" href="/tiki-view_forum_thread.php?locale=en-US&forumId=1&comments_threshold="whscheck="whscheck()&comments_parentId=2046&comments_offset=0&comments_per_page=20&thread_style=commentStyle_plain">« Prev</a>
<a class="prevnext" href="/tiki-view_forum_thread.php?locale=en-US&forumId=1&comments_threshold="whscheck="whscheck()&comments_parentId=2046&comments_offset=0&comments_per_page=20&thread_style=commentStyle_plain">1</a>
<span class="current_page">2</span>
<a class="prevnext" href="/tiki-view_forum_thread.php?locale=en-US&forumId=1&comments_threshold="whscheck="whscheck()&comments_parentId=2046&comments_offset=40&comments_per_page=20&thread_style=commentStyle_plain">3</a>
<a class="prevnext" href="/tiki-view_forum_thread.php?locale=en-US&forumId=1&comments_threshold="whscheck="whscheck()&comments_parentId=2046&comments_offset=60&comments_per_page=20&thread_style=commentStyle_plain">4</a>
<a class="prevnext" href="/tiki-view_forum_thread.php?locale=en-US&forumId=1&comments_threshold="whscheck="whscheck()&comments_parentId=2046&comments_offset=80&comments_per_page=20&thread_style=commentStyle_plain">5</a>
<a class="prevnext" href="/tiki-view_forum_thread.php?locale=en-US&forumId=1&comments_threshold="whscheck="whscheck()&comments_parentId=2046&comments_offset=40&comments_per_page=20&thread_style=commentStyle_plain">Next »</a>
</div>
| Reporter | ||
Comment 6•17 years ago
|
||
Assignee: smirkingsisyphus → reed
Status: REOPENED → ASSIGNED
Attachment #368846 -
Flags: review?(smirkingsisyphus)
Comment 7•17 years ago
|
||
1.0 is frozen and going out tomorrow, 1.1 freezes tomorrow and goes out next week. Pushing to 1.1.
Target Milestone: 1.0 → 1.1
| Reporter | ||
Comment 8•17 years ago
|
||
(In reply to comment #7)
> 1.0 is frozen and going out tomorrow, 1.1 freezes tomorrow and goes out next
> week. Pushing to 1.1.
Now that 1.0 is 0.9.5, does that mean 1.0 is going out next week? I would like this reviewed and pushed as soon as possible, especially considering how long the past ones have been delayed.
Target Milestone: 1.1 → 1.0
Updated•17 years ago
|
Attachment #368846 -
Flags: review?(smirkingsisyphus) → review+
Comment 9•17 years ago
|
||
Comment on attachment 368846 [details] [diff] [review]
Fix issue found in comment #4 along with other fixes - v1
Sorry for the delay.
Looks good.
| Reporter | ||
Comment 10•17 years ago
|
||
r23752/r23753
Status: ASSIGNED → RESOLVED
Closed: 17 years ago → 17 years ago
Resolution: --- → FIXED
Staging (http://support-stage.mozilla.org/tiki-view_forum_thread.php?locale=en-US&forumId=1&comments_threshold=%22whscheck=%22whscheck%28%29&comments_parentId=2046&comments_offset=20&comments_per_page=20&thread_style=commentStyle_plain):
<a class="prevnext" href="/tiki-view_forum_thread.php?locale=en-US&forumId=1&comments_threshold=%22whscheck%3D%22whscheck%28%29&comments_parentId=2046&comments_offset=0&comments_per_page=20&thread_style=commentStyle_plain">« Prev</a>
Verified FIXED
Status: RESOLVED → VERIFIED
Updated•16 years ago
|
Whiteboard: tiki_triage
Comment 12•16 years ago
|
||
Sentinel claims this vulnerability was re-introduced on 2009-09-28.
Vulnerable URLS:
http://support.mozilla.com/tiki-view_forum_thread.php?forumId=1&comments_parentId=215839&comments_grandParentId=%22whscheck=%22whscheck&comments_reply_threadId=215839&comments_offset=0&forumId=1
https://support.mozilla.com/tiki-view_forum_thread.php?comments_parentId=463957&%22whscheck=%22whscheck&forumId=1
http://support.mozilla.com/tiki-view_forum_thread.php?forumId=1&comments_parentId=215839&comments_grandParentId=&comments_reply_threadId=%22whscheck=%22whscheck&comments_offset=0&forumId=1
http://support.mozilla.com/tiki-view_forum_thread.php?locale=en-US&forumId=3&%22whscheck=%22whscheck&comments_parentId=431655&watch_event=forum_post_thread&watch_object=431655&watch_action=add
https://support.mozilla.com/tiki-view_forum_thread.php?locale=%22whscheck=%22whscheck&comments_parentId=198326&forumId=1
https://support.mozilla.com/tiki-view_forum_thread.php?locale=%22whscheck=%22whscheck&forumId=1&comments_parentId=459192&watch_event=forum_post_thread&watch_object=459192&watch_action=add
https://support.mozilla.com/tiki-view_forum_thread.php?locale=en-US&forumId=1&comments_parentId=459192&watch_event=forum_post_thread&watch_object=459192&watch_action=%22whscheck=%22whscheck
https://support.mozilla.com/tiki-view_forum_thread.php?locale=en-US&forumId=1&comments_parentId=459192&watch_event=%22whscheck=%22whscheck&watch_object=459192&watch_action=add
https://support.mozilla.com/tiki-view_forum_thread.php?locale=en-US&forumId=1&comments_parentId=459192&watch_event=forum_post_thread&watch_object=%22whscheck=%22whscheck&watch_action=add
http://support.mozilla.com/tiki-view_forum_thread.php?locale=en-US&forumId=3&comments_parentId=431655&watch_event=forum_post_thread&watch_object=%22whscheck=%22whscheck&watch_action=add
Status: VERIFIED → REOPENED
Resolution: FIXED → ---
| Reporter | ||
Updated•16 years ago
|
Assignee: reed → james
Target Milestone: 1.0 → ---
| Assignee | ||
Updated•16 years ago
|
Target Milestone: --- → 1.5
| Assignee | ||
Comment 13•16 years ago
|
||
We've had two releases since 2009-09-28 and a lot of these are looking closed--in several of them, I don't see "whscheck" in the output at all. Is there anything more up to date?
| Assignee | ||
Comment 14•16 years ago
|
||
A WHS scan on 11/12 says this vulnerability is closed (see the XSS bugs in 1.4.2).
Status: REOPENED → RESOLVED
Closed: 17 years ago → 16 years ago
Resolution: --- → FIXED
Verified per comment 14 (James said he conferred with justdave).
Status: RESOLVED → VERIFIED
Updated•16 years ago
|
Whiteboard: tiki_triage → tiki_test
Comment 16•12 years ago
|
||
Adding keywords to bugs for metrics, no action required. Sorry about bugmail spam.
Keywords: wsec-xss
Comment 17•10 years ago
|
||
These bugs are all resolved, so I'm removing the security flag from them.
Group: websites-security
You need to log in
before you can comment on or make changes to this bug.
Description
•