#1054 [Opn->Csd]: SECURITY: critical - bug system does not escape HTML in titles
| From: | mj@php.net | Date: | Tue, 23 Mar 2004 07:24:36 +0000 |
| Subject: | #1054 [Opn->Csd]: SECURITY: critical - bug system does not escape HTML in titles | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-26657@lists.php.net to get a copy of this message | ||
ID: 1054
Updated by: mj@php.net
Reported By: alan at akbkhome dot com
-Status: Open
+Status: Closed
Bug Type: Bug System
Operating System: na
PHP Version: 4.3.4
New Comment:
This bug has been fixed in CVS.
In case this was a documentation problem, the fix will show up at the
end of next Sunday (CET) on pear.php.net.
In case this was a pear.php.net website problem, the change will show
up on the website in short time.
Thank you for the report, and for helping us make PEAR better.
Previous Comments:
------------------------------------------------------------------------
[2004-03-23 01:23:37] alan at akbkhome dot com
yeap - thats the one
------------------------------------------------------------------------
[2004-03-22 20:34:04] danielc at analysisandsolutions dot com
The only place I found in bugs that presents the sdesc field unescaped
is on line 87 of report.php, where $row['sdesc'] should be
htmlspecialchars($row['sdesc']).
This section of code gets presented to the submittor once they
initially submit a bug report and bugs are found that appear similar to
the one they're trying to submit.
Is this where you saw the problem?
------------------------------------------------------------------------
[2004-03-22 09:36:45] alan at akbkhome dot com
Description:
------------
submitting a bug to HTML_javascript produces a search result with a bug
on Flexy that as <textarea> in the title..
- this appears as a text area..
- we are suceptable to cross site scripting!!!!!!!
** need to htmlspecialchars title !
------------------------------------------------------------------------
--
Edit this bug report at http://pear.php.net/bugs/bug.php?id=1054&edit=1