#1054 [Opn->Csd]: SECURITY: critical - bug system does not escape HTML in titles

From: Date: Tue, 23 Mar 2004 07:24:36 +0000
Subject: #1054 [Opn->Csd]: SECURITY: critical - bug system does not escape HTML in titles
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-26657@lists.php.net to get a copy of this message
ID: 1054 Updated by: mj@php.net Reported By: alan at akbkhome dot com -Status: Open +Status: Closed Bug Type: Bug System Operating System: na PHP Version: 4.3.4 New Comment: This bug has been fixed in CVS. In case this was a documentation problem, the fix will show up at the end of next Sunday (CET) on pear.php.net. In case this was a pear.php.net website problem, the change will show up on the website in short time. Thank you for the report, and for helping us make PEAR better. Previous Comments: ------------------------------------------------------------------------ [2004-03-23 01:23:37] alan at akbkhome dot com yeap - thats the one ------------------------------------------------------------------------ [2004-03-22 20:34:04] danielc at analysisandsolutions dot com The only place I found in bugs that presents the sdesc field unescaped is on line 87 of report.php, where $row['sdesc'] should be htmlspecialchars($row['sdesc']). This section of code gets presented to the submittor once they initially submit a bug report and bugs are found that appear similar to the one they're trying to submit. Is this where you saw the problem? ------------------------------------------------------------------------ [2004-03-22 09:36:45] alan at akbkhome dot com Description: ------------ submitting a bug to HTML_javascript produces a search result with a bug on Flexy that as <textarea> in the title.. - this appears as a text area.. - we are suceptable to cross site scripting!!!!!!! ** need to htmlspecialchars title ! ------------------------------------------------------------------------ -- Edit this bug report at http://pear.php.net/bugs/bug.php?id=1054&edit=1

« previous php.pear.dev (#26657) next »