[Webkit-unassigned] [Bug 66588] XSS filter bypass via non-standard URL encoding

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Fri Sep 2 11:23:08 PDT 2011


https://bugs.webkit.org/show_bug.cgi?id=66588





--- Comment #4 from Thomas Sepez <tsepez at chromium.org>  2011-09-02 11:23:08 PST ---
(From update of attachment 106094)
View in context: https://bugs.webkit.org/attachment.cgi?id=106094&action=review

> LayoutTests/http/tests/security/xssAuditor/script-tag-with-fancy-unicode2.html:13
> +</iframe>

Really need to stick some high-valued codepoints in here -- that may show the *p bug above.  Also %252525u0061 should be tried as well to test interaction between the two decoders.

-- 
Configure bugmail: https://bugs.webkit.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.



More information about the webkit-unassigned mailing list