Issue Details (XML | Word | Printable)

Key: JM-629
Type: Bug Bug
Status: Closed Closed
Resolution: Fixed
Priority: Blocker Blocker
Assignee: Daniel Henninger
Reporter: Matt Tucker
Votes: 7
Watchers: 3
Operations

If you were logged in you would be able to see more operations.
Openfire (ARCHIVED)

Additional cross-site scripting bugs in login

Created: 04/07/06 08:38 PM   Updated: 11/12/08 09:41 AM
Component/s: Admin Console
Affects Version/s: 2.6.0
Fix Version/s: 3.6.0

Time Tracking:
Not Specified

Issue Links:
Related to

Resolution Date: 08/25/08 06:48 PM
Acceptance Test - Add?: No


 Description  « Hide
Additional cross-site scripting attacks possible in the login form.

 All   Comments   Work Log   Change History   FishEye      Sort Order: Ascending order - Click to sort in descending order
LG added a comment - 05/21/08 09:45 PM
Hi,

I really wonder why it take so long to resolve this issue. Just ignoring the parsed parameters (everything behind the ?) would be fine to fix this issue.
Of course one would no longer be able to access URL's directly and to set the username but that's how other applications solve this issue.

LG


Daniel Henninger added a comment - 05/22/08 03:21 AM
Patience =) I aim to fix these and some other assorted issues for 3.5.2!