Closed Bug 812769 Opened 13 years ago Closed 12 years ago

wiki.mozilla.org xss in URL JsUnit 2.2

Categories

(Websites :: wiki.mozilla.org, defect)

defect
Not set
normal

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: insecurity.ro, Unassigned)

Details

(Keywords: reporter-external, wsec-xss, Whiteboard: [site:wiki.mozilla.org])

Attachments

(1 file)

162.24 KB, image/jpeg
Details
Attached image xss.jpg
User Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.28) Gecko/20120306 Firefox/3.6.28 Build ID: 20120306064154 Steps to reproduce: Hello again, i found ..hmm..interesting thing. Actual results: Today i read about FCKeditor and try and try with https://wiki.mozilla.org/extensions/FCKeditor/fckeditor/editor/filemanager/connectors/uploadtest.html , but this impossible, because .."This file uploader is disabled." And i found something interesting another..and this work!)) https://wiki.mozilla.org/extensions/FCKeditor/fckeditor/_test/automated/_jsunit/testRunner.html?testpage=%27;alert%28String.fromCharCode%2888,83,83%29%29//%27;alert%28String.fromCharCode%2888,83,83%29%29//%22;alert%28String.fromCharCode%2888,83,83%29%29//%22;alert%28String.fromCharCode%2888,83,83%29%29//--%3E%3C/SCRIPT%3E%22%3E%27%3E%3CSCRIPT%3Ealert%28String.fromCharCode%2888,83,83%29%29%3C/SCRIPT%3E I use for test Mozilla Firefox browser. Yeah, this is a very interesting xss. Today i all day with xss, great day)) Like this. Expected results: Steal cookies, etc.
Status: UNCONFIRMED → NEW
Ever confirmed: true
Flags: sec-bounty?
Keywords: wsec-xss
I think a lot of web sites have a problem with this bug. I think this should be fixed and reported to the developers.
Assignee: nobody → rforbes
Component: General → wiki.mozilla.org
Product: www.mozilla.org → Websites
Whiteboard: [site:wiki.mozilla.org]
Assignee: rforbes → nobody
XSS on our wiki sites are not eligible for our bounty program. Since it's 3rd party software we are only interested in bugs that affect the machine integrity, not the wiki content.
Assignee: nobody → rforbes
Flags: sec-bounty? → sec-bounty-
Assignee: rforbes → nobody
This is fixed because FCKeditor was removed in the wikimo upgrade per bug 738257.
Status: NEW → RESOLVED
Closed: 12 years ago
Resolution: --- → FIXED
Group: websites-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: