Bug #66722 [Opn->Fbk]: Cross-site Scripting
| From: | bjori@php.net | Date: | Sun, 16 Feb 2014 19:24:17 +0000 |
| Subject: | Bug #66722 [Opn->Fbk]: Cross-site Scripting | ||
| References: | 1 | Groups: | php.webmaster |
| Request: | Send a blank email to php-webmaster+get-18345@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66722&edit=1
ID: 66722
Updated by: bjori@php.net
Reported by: allan dot jay71 at yahoo dot com
Summary: Cross-site Scripting
-Status: Open
+Status: Feedback
Type: Bug
Package: Website problem
Operating System: Windows 7
PHP Version: 5.6.0alpha2
Block user comment: N
Private report: N
New Comment:
where did you upload that svg?
Previous Comments:
------------------------------------------------------------------------
[2014-02-16 05:49:07] allan dot jay71 at yahoo dot com
Description:
------------
I uploaded a .SVG which contained a malicious XSS Code.
code used: "><img src=x onerror=alert(document.cookie)>
Test script:
---------------
Code inside the .SVG FILE: "><img src=x onerror=alert(document.cookie)>
Expected result:
----------------
the XSS Code will appear
Actual result:
--------------
Trying
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66722&edit=1