geronimo-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Greg Wilkins (JIRA)" <>
Subject [jira] Created: (GERONIMO-1474) Cross site scripting vulnerabilites
Date Sun, 15 Jan 2006 12:27:20 GMT
Cross site scripting vulnerabilites

         Key: GERONIMO-1474
     Project: Geronimo
        Type: Bug
  Components: console  
    Versions: 1.0    
    Reporter: Greg Wilkins
     Fix For: 1.0.1

Reported by oliver karow:

The Web-Access-Log viewer does no filtering for html-/script-tags, and
therefore allows attacks against the user of the admin-console:"/><script>alert(document.cookie)</script>

Also reported:

The first one is a classical cross-site scripting in the jsp-examples:"/><script>alert('Gotcha')</script>

This message is automatically generated by JIRA.
If you think it was sent incorrectly contact one of the administrators:
For more information on JIRA, see:

View raw message