Bug 30242
| Summary: | [XSSAuditor] IFrame JavaScript URLs that are URL-encoded twice can by bypass the XSSAuditor | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Product: | WebKit | Reporter: | Daniel Bates <dbates> | ||||||
| Component: | WebCore Misc. | Assignee: | Daniel Bates <dbates> | ||||||
| Status: | RESOLVED FIXED | ||||||||
| Severity: | Normal | CC: | abarth, sam | ||||||
| Priority: | P2 | Keywords: | XSSAuditor | ||||||
| Version: | 528+ (Nightly build) | ||||||||
| Hardware: | PC | ||||||||
| OS: | OS X 10.5 | ||||||||
| URL: | http://good.webblaze.org/dbates/xsstest.php?q=%3Ciframe%20src=%22javascript:%20%250Aalert(/XSS/)%22%3E%3C/iframe%3E | ||||||||
| Attachments: |
|
||||||||
2009-10-11 16:28 PDT, Daniel Bates
2009-10-11 20:56 PDT, Daniel Bates