[Webkit-unassigned] [Bug 26899] New: XSSAuditor shouldn't strip control characters

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Wed Jul 1 13:21:57 PDT 2009


https://bugs.webkit.org/show_bug.cgi?id=26899

           Summary: XSSAuditor shouldn't strip control characters
           Product: WebKit
           Version: 528+ (Nightly build)
          Platform: All
               URL: https://xenon.stanford.edu/~collinj/test/ie8xss/xsstest.
                    php?q=<script>alert(/XSS/)//h%01</script>
        OS/Version: All
            Status: NEW
          Severity: Normal
          Priority: P2
         Component: WebCore Misc.
        AssignedTo: webkit-unassigned at lists.webkit.org
        ReportedBy: abarth at webkit.org
                CC: sam at webkit.org, dbates at berkeley.edu


Test case:

https://xenon.stanford.edu/~collinj/test/ie8xss/xsstest.php?q=<script>alert(/XSS/)//h%01</script>


-- 
Configure bugmail: https://bugs.webkit.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.



More information about the webkit-unassigned mailing list