| Summary: |
[XSSAuditor] JavaScript URLs that are URL-encoded twice can by bypass the XSSAuditor |
| Product: |
WebKit
|
Reporter: |
Daniel Bates <dbates> |
| Component: |
WebCore Misc. | Assignee: |
Nobody <webkit-unassigned> |
| Status: |
RESOLVED
FIXED
|
|
|
| Severity: |
Normal
|
CC: |
abarth, mario.heiderich, sam
|
| Priority: |
P2
|
Keywords: |
XSSAuditor |
| Version: |
528+ (Nightly build) | |
|
| Hardware: |
All | |
|
| OS: |
All | |
|
| URL: |
http://eaea.sirdarckcat.net/xss.php?html_xss=<iframe+src="javascript:'1%25251';alert(document.domain)">
|
| Bug Depends on: |
|
|
|
| Bug Blocks: |
29278
|
|
|
| Attachments: |
|
2009-09-19 14:52 PDT, Daniel Bates
2009-09-19 16:17 PDT, Daniel Bates
2009-09-19 17:55 PDT, Daniel Bates