Summary: |
[XSSAuditor] JavaScript URLs that are URL-encoded twice can by bypass the XSSAuditor |
Product: |
WebKit
|
Reporter: |
Daniel Bates <dbates> |
Component: |
WebCore Misc. | Assignee: |
Nobody <webkit-unassigned> |
Status: |
RESOLVED
FIXED
|
|
|
Severity: |
Normal
|
CC: |
abarth, mario.heiderich, sam
|
Priority: |
P2
|
Keywords: |
XSSAuditor |
Version: |
528+ (Nightly build) | |
|
Hardware: |
All | |
|
OS: |
All | |
|
URL: |
http://eaea.sirdarckcat.net/xss.php?html_xss=<iframe+src="javascript:'1%25251';alert(document.domain)">
|
Bug Depends on: |
|
|
|
Bug Blocks: |
29278
|
|
|
Attachments: |
|
2009-09-19 14:52 PDT, Daniel Bates
2009-09-19 16:17 PDT, Daniel Bates
2009-09-19 17:55 PDT, Daniel Bates