Bug #66722 [Opn->Fbk]: Cross-site Scripting

From: Date: Sun, 16 Feb 2014 19:24:17 +0000
Subject: Bug #66722 [Opn->Fbk]: Cross-site Scripting
References: 1  Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-18345@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66722&edit=1 ID: 66722 Updated by: bjori@php.net Reported by: allan dot jay71 at yahoo dot com Summary: Cross-site Scripting -Status: Open +Status: Feedback Type: Bug Package: Website problem Operating System: Windows 7 PHP Version: 5.6.0alpha2 Block user comment: N Private report: N New Comment: where did you upload that svg? Previous Comments: ------------------------------------------------------------------------ [2014-02-16 05:49:07] allan dot jay71 at yahoo dot com Description: ------------ I uploaded a .SVG which contained a malicious XSS Code. code used: "><img src=x onerror=alert(document.cookie)> Test script: --------------- Code inside the .SVG FILE: "><img src=x onerror=alert(document.cookie)> Expected result: ---------------- the XSS Code will appear Actual result: -------------- Trying ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66722&edit=1

« previous php.webmaster (#18345) next »