<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>83794</bug_id>
          
          <creation_ts>2012-04-12 11:04:04 -0700</creation_ts>
          <short_desc>Typos in LayoutTests/http/tests/security/xssAuditor/script-tag-inside-svg-tag*.html</short_desc>
          <delta_ts>2012-04-12 11:57:47 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>WebCore Misc.</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>XSSAuditor</keywords>
          <priority>P2</priority>
          <bug_severity>Trivial</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Thomas Sepez">tsepez</reporter>
          <assigned_to name="Thomas Sepez">tsepez</assigned_to>
          <cc>abarth</cc>
    
    <cc>dbates</cc>
    
    <cc>webkit.review.bot</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>601361</commentid>
    <comment_count>0</comment_count>
    <who name="Thomas Sepez">tsepez</who>
    <bug_when>2012-04-12 11:04:04 -0700</bug_when>
    <thetext>Several changes needed to make the XSS in these test cases fire against actual vulnerable browser:
- %24 appears in a few places where %23 is required.  
- Appears webkit&apos;s httpd will terminate query parameters at unencoded semicolons ( ; )
- Misordered &lt;/svg&gt;&lt;/script&gt; tags.

The tests are still valid, but it is more intuitive to see the XSS pop up.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>601378</commentid>
    <comment_count>1</comment_count>
      <attachid>136937</attachid>
    <who name="Thomas Sepez">tsepez</who>
    <bug_when>2012-04-12 11:17:20 -0700</bug_when>
    <thetext>Created attachment 136937
Patch

Only tests modified.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>601407</commentid>
    <comment_count>2</comment_count>
      <attachid>136937</attachid>
    <who name="WebKit Review Bot">webkit.review.bot</who>
    <bug_when>2012-04-12 11:57:41 -0700</bug_when>
    <thetext>Comment on attachment 136937
Patch

Clearing flags on attachment: 136937

Committed r114010: &lt;http://trac.webkit.org/changeset/114010&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>601408</commentid>
    <comment_count>3</comment_count>
    <who name="WebKit Review Bot">webkit.review.bot</who>
    <bug_when>2012-04-12 11:57:47 -0700</bug_when>
    <thetext>All reviewed patches have been landed.  Closing bug.</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>136937</attachid>
            <date>2012-04-12 11:17:20 -0700</date>
            <delta_ts>2012-04-12 11:57:41 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>patch_83794.txt</filename>
            <type>text/plain</type>
            <size>3749</size>
            <attacher name="Thomas Sepez">tsepez</attacher>
            
              <data encoding="base64">SW5kZXg6IExheW91dFRlc3RzL0NoYW5nZUxvZwo9PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBMYXlvdXRUZXN0cy9D
aGFuZ2VMb2cJKHJldmlzaW9uIDExNDAwNCkKKysrIExheW91dFRlc3RzL0NoYW5nZUxvZwkod29y
a2luZyBjb3B5KQpAQCAtMSwzICsxLDE4IEBACisyMDEyLTA0LTEyICBUb20gU2VwZXogIDx0c2Vw
ZXpAY2hyb21pdW0ub3JnPgorCisgICAgICAgIFR5cG9zIGluIExheW91dFRlc3RzL2h0dHAvdGVz
dHMvc2VjdXJpdHkveHNzQXVkaXRvci9zY3JpcHQtdGFnLWluc2lkZS1zdmctdGFnKi5odG1sCisg
ICAgICAgIGh0dHBzOi8vYnVncy53ZWJraXQub3JnL3Nob3dfYnVnLmNnaT9pZD04Mzc5NAorCisg
ICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorCisgICAgICAgIFNldmVyYWwgY2hh
bmdlcyBuZWVkZWQgdG8gbWFrZSB0aGUgWFNTIGluIHRoZXNlIHRlc3QgY2FzZXMgZmlyZSBhZ2Fp
bnN0IGFjdHVhbAorICAgICAgICB2dWxuZXJhYmxlIGJyb3dzZXJzLiBUaGUgdGVzdHMgd2VyZSBz
dGlsbCB2YWxpZCwgYnV0IGl0IGlzIG1vcmUgaGVscGZ1bCB0byBzZWUKKyAgICAgICAgdGhlIFhT
UyBwb3AgdXAuCisKKyAgICAgICAgKiBodHRwL3Rlc3RzL3NlY3VyaXR5L3hzc0F1ZGl0b3Ivc2Ny
aXB0LXRhZy1pbnNpZGUtc3ZnLXRhZy5odG1sOgorICAgICAgICAqIGh0dHAvdGVzdHMvc2VjdXJp
dHkveHNzQXVkaXRvci9zY3JpcHQtdGFnLWluc2lkZS1zdmctdGFnMi5odG1sOgorICAgICAgICAq
IGh0dHAvdGVzdHMvc2VjdXJpdHkveHNzQXVkaXRvci9zY3JpcHQtdGFnLWluc2lkZS1zdmctdGFn
My5odG1sOgorCiAyMDEyLTA0LTEyICBQaGlsaXBwZSBOb3JtYW5kICA8cG5vcm1hbmRAaWdhbGlh
LmNvbT4KIAogICAgICAgICBVbnJldmlld2VkLCBHVEsgdGVzdF9leHBlY3RhdGlvbnMuCkluZGV4
OiBMYXlvdXRUZXN0cy9odHRwL3Rlc3RzL3NlY3VyaXR5L3hzc0F1ZGl0b3Ivc2NyaXB0LXRhZy1p
bnNpZGUtc3ZnLXRhZzIuaHRtbAo9PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBMYXlvdXRUZXN0cy9odHRwL3Rlc3Rz
L3NlY3VyaXR5L3hzc0F1ZGl0b3Ivc2NyaXB0LXRhZy1pbnNpZGUtc3ZnLXRhZzIuaHRtbAkocmV2
aXNpb24gMTEzOTE5KQorKysgTGF5b3V0VGVzdHMvaHR0cC90ZXN0cy9zZWN1cml0eS94c3NBdWRp
dG9yL3NjcmlwdC10YWctaW5zaWRlLXN2Zy10YWcyLmh0bWwJKHdvcmtpbmcgY29weSkKQEAgLTks
NyArOSw3IEBAIGlmICh3aW5kb3cubGF5b3V0VGVzdENvbnRyb2xsZXIpIHsKIDwvc2NyaXB0Pgog
PC9oZWFkPgogPGJvZHk+Ci08aWZyYW1lIHNyYz0iaHR0cDovL2xvY2FsaG9zdDo4MDAwL3NlY3Vy
aXR5L3hzc0F1ZGl0b3IvcmVzb3VyY2VzL2VjaG8taW50ZXJ0YWcucGw/Y2x1dHRlcj08ZGl2Pjxp
Png8L2k+PC9kaXY+JnE9PHN2Zz48c2NyaXB0PjwhLS0mcTI9LS0+JTI2JTI0eDBhO2FsZXJ0JTI2
JTIzeDI5O1N0cmluZy5mcm9tQ2hhckNvZGUoMHg1OCwweDUzLDB4NTMpKTwvc3ZnPjwvc2NyaXB0
PiI+Cis8aWZyYW1lIHNyYz0iaHR0cDovL2xvY2FsaG9zdDo4MDAwL3NlY3VyaXR5L3hzc0F1ZGl0
b3IvcmVzb3VyY2VzL2VjaG8taW50ZXJ0YWcucGw/Y2x1dHRlcj08ZGl2PjxpPng8L2k+PC9kaXY+
JnE9PHN2Zz48c2NyaXB0PjwhLS0mcTI9LS0+JTI2JTIzeDBhJTNiYWxlcnQlMjYlMjN4MjglM2JT
dHJpbmcuZnJvbUNoYXJDb2RlKDB4NTgsMHg1MywweDUzKSk8L3NjcmlwdD48L3N2Zz4iPgogPC9p
ZnJhbWU+CiBFbnN1cmVzIEhUTUwgZW50aXRpZXMgYXJlIHJlY29nbml6ZWQgaW4gc2NyaXB0IGJs
b2NrcyBpbiBhIGNvbnRleHQgd2hlcmUgQ0RBVEEgaXMgYWxsb3dlZCBldmVuIHdpdGggJmx0OyEt
LSBjb21tZW50cyAtLSZndDsuCiA8L2JvZHk+CkluZGV4OiBMYXlvdXRUZXN0cy9odHRwL3Rlc3Rz
L3NlY3VyaXR5L3hzc0F1ZGl0b3Ivc2NyaXB0LXRhZy1pbnNpZGUtc3ZnLXRhZzMuaHRtbAo9PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09Ci0tLSBMYXlvdXRUZXN0cy9odHRwL3Rlc3RzL3NlY3VyaXR5L3hzc0F1ZGl0b3Ivc2Ny
aXB0LXRhZy1pbnNpZGUtc3ZnLXRhZzMuaHRtbAkocmV2aXNpb24gMTEzOTE5KQorKysgTGF5b3V0
VGVzdHMvaHR0cC90ZXN0cy9zZWN1cml0eS94c3NBdWRpdG9yL3NjcmlwdC10YWctaW5zaWRlLXN2
Zy10YWczLmh0bWwJKHdvcmtpbmcgY29weSkKQEAgLTksNyArOSw3IEBAIGlmICh3aW5kb3cubGF5
b3V0VGVzdENvbnRyb2xsZXIpIHsKIDwvc2NyaXB0PgogPC9oZWFkPgogPGJvZHk+Ci08aWZyYW1l
IHNyYz0iaHR0cDovL2xvY2FsaG9zdDo4MDAwL3NlY3VyaXR5L3hzc0F1ZGl0b3IvcmVzb3VyY2Vz
L2VjaG8taW50ZXJ0YWcucGw/Y2x1dHRlcj08c2NyaXB0PmFsZXJ0KDEpPC9zY3JpcHQ+JnE9PHN2
Zz48c2NyaXB0PiZxMj1hbGVydCgwKTs8L3NjcmlwdD48L3N2Zz4iPgorPGlmcmFtZSBzcmM9Imh0
dHA6Ly9sb2NhbGhvc3Q6ODAwMC9zZWN1cml0eS94c3NBdWRpdG9yL3Jlc291cmNlcy9lY2hvLWlu
dGVydGFnLnBsP2NsdXR0ZXI9PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0PiZxPTxzdmc+PHNjcmlw
dD4mcTI9YWxlcnQoMCk8L3NjcmlwdD48L3N2Zz4iPgogPC9pZnJhbWU+CiBFbnN1cmVzIEhUTUwg
ZW50aXRpZXMgYXJlIHJlY29nbml6ZWQgaW4gc2NyaXB0IGJsb2NrcyBpbiBhIGNvbnRleHQgd2hl
cmUgQ0RBVEEgaXMgYWxsb3dlZCBldmVuIHdpdGggbmVzdGVkIHNjcmlwdCBibG9ja3MuCiA8L2Jv
ZHk+CkluZGV4OiBMYXlvdXRUZXN0cy9odHRwL3Rlc3RzL3NlY3VyaXR5L3hzc0F1ZGl0b3Ivc2Ny
aXB0LXRhZy1pbnNpZGUtc3ZnLXRhZy5odG1sCj09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0tIExheW91dFRlc3RzL2h0
dHAvdGVzdHMvc2VjdXJpdHkveHNzQXVkaXRvci9zY3JpcHQtdGFnLWluc2lkZS1zdmctdGFnLmh0
bWwJKHJldmlzaW9uIDExMzkxOSkKKysrIExheW91dFRlc3RzL2h0dHAvdGVzdHMvc2VjdXJpdHkv
eHNzQXVkaXRvci9zY3JpcHQtdGFnLWluc2lkZS1zdmctdGFnLmh0bWwJKHdvcmtpbmcgY29weSkK
QEAgLTksNyArOSw3IEBAIGlmICh3aW5kb3cubGF5b3V0VGVzdENvbnRyb2xsZXIpIHsKIDwvc2Ny
aXB0PgogPC9oZWFkPgogPGJvZHk+Ci08aWZyYW1lIHNyYz0iaHR0cDovL2xvY2FsaG9zdDo4MDAw
L3NlY3VyaXR5L3hzc0F1ZGl0b3IvcmVzb3VyY2VzL2VjaG8taW50ZXJ0YWcucGw/cT08c3ZnPjxz
Y3JpcHQ+Ly8lMjYlMjR4MGE7YWxlcnQlMjYlMjN4Mjk7U3RyaW5nLmZyb21DaGFyQ29kZSgweDU4
LDB4NTMsMHg1MykpPC9zdmc+PC9zY3JpcHQ+Ij4KKzxpZnJhbWUgc3JjPSJodHRwOi8vbG9jYWxo
b3N0OjgwMDAvc2VjdXJpdHkveHNzQXVkaXRvci9yZXNvdXJjZXMvZWNoby1pbnRlcnRhZy5wbD9x
PTxzdmc+PHNjcmlwdD4lMmYlMmYlMjYlMjN4MGElM2JhbGVydCUyNiUyM3gyOCUzYlN0cmluZy5m
cm9tQ2hhckNvZGUoMHg1OCwweDUzLDB4NTMpKTwvc2NyaXB0Pjwvc3ZnPiI+CiA8L2lmcmFtZT4K
IEVuc3VyZXMgSFRNTCBlbnRpdGllcyBhcmUgcmVjb2duaXplZCBpbiBzY3JpcHQgYmxvY2tzIGlu
IGEgY29udGV4dCB3aGVyZSBDREFUQSBpcyBhbGxvd2VkLgogPC9ib2R5Pgo=
</data>

          </attachment>
      

    </bug>

</bugzilla>