#1054 [Opn]: SECURITY: critical - bug system does not escape HTML in titles

From: Date: Tue, 23 Mar 2004 06:23:37 +0000
Subject: #1054 [Opn]: SECURITY: critical - bug system does not escape HTML in titles
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-26654@lists.php.net to get a copy of this message
ID: 1054 User updated by: alan at akbkhome dot com Reported By: alan at akbkhome dot com Status: Open Bug Type: Bug System Operating System: na PHP Version: 4.3.4 New Comment: yeap - thats the one Previous Comments: ------------------------------------------------------------------------ [2004-03-22 20:34:04] danielc at analysisandsolutions dot com The only place I found in bugs that presents the sdesc field unescaped is on line 87 of report.php, where $row['sdesc'] should be htmlspecialchars($row['sdesc']). This section of code gets presented to the submittor once they initially submit a bug report and bugs are found that appear similar to the one they're trying to submit. Is this where you saw the problem? ------------------------------------------------------------------------ [2004-03-22 09:36:45] alan at akbkhome dot com Description: ------------ submitting a bug to HTML_javascript produces a search result with a bug on Flexy that as <textarea> in the title.. - this appears as a text area.. - we are suceptable to cross site scripting!!!!!!! ** need to htmlspecialchars title ! ------------------------------------------------------------------------ -- Edit this bug report at http://pear.php.net/bugs/bug.php?id=1054&edit=1

« previous php.pear.dev (#26654) next »