Bug 30242
Summary: | [XSSAuditor] IFrame JavaScript URLs that are URL-encoded twice can by bypass the XSSAuditor | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Daniel Bates <dbates> | ||||||
Component: | WebCore Misc. | Assignee: | Daniel Bates <dbates> | ||||||
Status: | RESOLVED FIXED | ||||||||
Severity: | Normal | CC: | abarth, sam | ||||||
Priority: | P2 | Keywords: | XSSAuditor | ||||||
Version: | 528+ (Nightly build) | ||||||||
Hardware: | PC | ||||||||
OS: | OS X 10.5 | ||||||||
URL: | http://good.webblaze.org/dbates/xsstest.php?q=%3Ciframe%20src=%22javascript:%20%250Aalert(/XSS/)%22%3E%3C/iframe%3E | ||||||||
Attachments: |
|
2009-10-11 16:28 PDT, Daniel Bates
2009-10-11 20:56 PDT, Daniel Bates