[JIRA] Fermé: (OFBIZ-559) Cross Site Scripting Vulnerability (XSS)

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

[JIRA] Fermé: (OFBIZ-559) Cross Site Scripting Vulnerability (XSS)

JIRA jira@ofbiz.org
     [ http://jira.undersunconsulting.com/browse/OFBIZ-559?page=all ]
     
Jacques Le Roux closed OFBIZ-559:
---------------------------------

     Assign To: Jacques Le Roux  (was: Jira Administrator)
    Resolution: Duplicate

Replaced by http://issues.apache.org/jira/browse/OFBIZ-260

> Cross Site Scripting Vulnerability (XSS)
> ----------------------------------------
>
>          Key: OFBIZ-559
>          URL: http://jira.undersunconsulting.com/browse/OFBIZ-559
>      Project: [OFBiz] Open For Business
>         Type: Bug
>     Reporter: Oliver Lietz
>     Assignee: Jacques Le Roux

>
>
> *Very* simple test:
> /ecommerce/control/keywordsearch?SEARCH_STRING=<script>alert("XSS");</script>
> Other components beside ecommerce are also affected.

--
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators:
   http://jira.undersunconsulting.com/secure/Administrators.jspa
-
For more information on JIRA, see:
   http://www.atlassian.com/software/jira