View Issue Details

IDProjectCategoryView StatusLast Update
0000207Main CAcert Websitesource codepublic2013-11-20 22:23
Reporterblshkv Assigned To 
PrioritynormalSeveritymajorReproducibilityalways
Status closedResolutionfixed 
Fixed in Version2009 Q2 
Summary0000207: [security bug] cross site scripting
DescriptionXSS in the follow files:
https://www.test1.cacert.at/ac.php?id=<script>alert('xss')</script>
https://www.test1.cacert.at/account/50.php?userid="><script>alert('XSS')</script>
    the same with "email" parameter.
TagsNo tags attached.
Reviewed by
Test Instructions

Activities

duane

2006-04-21 06:46

developer   ~0000166

files moved out of webroot + ac.php updated to use intval()

bluec

2006-04-24 05:40

manager   ~0000195

Change not yet visible in tarball.

Sourcerer

2009-04-26 16:31

administrator   ~0001384

Bug had been fixed.

NEOatNHNG

2012-05-30 21:17

administrator   ~0003040

Closing issues that have been resolved more than one year ago…

Issue History

Date Modified Username Field Change
2006-04-16 10:53 blshkv New Issue
2006-04-21 06:46 duane Status new => closed
2006-04-21 06:46 duane Note Added: 0000166
2006-04-21 06:46 duane Resolution open => fixed
2006-04-21 06:46 duane Fixed in Version => production
2006-04-24 05:40 bluec Note Added: 0000195
2006-04-24 05:40 bluec Assigned To => bluec
2006-04-24 05:40 bluec Status closed => needs work
2009-04-26 16:31 Sourcerer Note Added: 0001384
2009-04-26 16:31 Sourcerer Assigned To bluec =>
2009-04-26 16:31 Sourcerer Status needs work => solved?
2012-05-30 21:17 NEOatNHNG Note Added: 0003040
2012-05-30 21:17 NEOatNHNG Status solved? => closed
2013-01-14 08:05 Werner Dworak Fixed in Version => 2009 Q2
2013-11-20 22:23 NEOatNHNG View Status private => public