#1054 [Com]: SECURITY: critical - bug system does not escape HTML in titles
| From: | danielc at analysisandsolutions dot com | Date: | Tue, 23 Mar 2004 01:34:04 +0000 |
| Subject: | #1054 [Com]: SECURITY: critical - bug system does not escape HTML in titles | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-26650@lists.php.net to get a copy of this message | ||
ID: 1054
Comment by: danielc at analysisandsolutions dot com
Reported By: alan at akbkhome dot com
Status: Open
Bug Type: Bug System
Operating System: na
PHP Version: 4.3.4
New Comment:
The only place I found in bugs that presents the sdesc field unescaped
is on line 87 of report.php, where $row['sdesc'] should be
htmlspecialchars($row['sdesc']).
This section of code gets presented to the submittor once they
initially submit a bug report and bugs are found that appear similar to
the one they're trying to submit.
Is this where you saw the problem?
Previous Comments:
------------------------------------------------------------------------
[2004-03-22 09:36:45] alan at akbkhome dot com
Description:
------------
submitting a bug to HTML_javascript produces a search result with a bug
on Flexy that as <textarea> in the title..
- this appears as a text area..
- we are suceptable to cross site scripting!!!!!!!
** need to htmlspecialchars title !
------------------------------------------------------------------------
--
Edit this bug report at http://pear.php.net/bugs/bug.php?id=1054&edit=1