View Issue Details

IDProjectCategoryView StatusLast Update
0000585Main CAcert Websitemiscpublic2013-07-09 22:39
Reporterraybellis Assigned To 
PrioritynormalSeverityminorReproducibilityalways
Status closedResolutionfixed 
Product Version2008 
Summary0000585: Issues with escaping on web-site e-mail forms
DescriptionThe contact forms seem to have problems with escaping quote characters (single and double variety)

If I put one in the form re-appears with backslash escaping, and then if I resubmit it the backslashes themselves get escaped.
TagsNo tags attached.
Reviewed by
Test Instructions

Relationships

related to 0001162 fix availableINOPIAE calcutate (the passwords) hash in php instead of in mysql -> \\ 
related to 0001097 closedNEOatNHNG Special characters which have no HTML-entities are not properly escaped 

Activities

Sourcerer

2008-08-04 15:49

administrator   ~0001127

Which URL is that contact form? Please provide screenshots to philipp@cacert.org

Uli60

2013-07-09 22:37

updater   ~0004113

Last edited: 2013-07-09 22:38

sent text via contact form:
---------------------------------
https://bugs.cacert.org/view.php?id=585

one backslash \
one aphostrophe '
german umlauts: ÄäÖöÜüß
doppelte Anfuehrungszeichen "
---------------------------------

results in:
one backslash \
one aphostrophe '
german umlauts: ÄäÖöÜüß
doppelte Anfuehrungszeichen "

so no further problems.

INOPIAE

2013-07-09 22:39

updater   ~0004114

fixed in the mean time by other patches eg 1097

Issue History

Date Modified Username Field Change
2008-08-04 13:22 raybellis New Issue
2008-08-04 15:49 Sourcerer Note Added: 0001127
2013-01-11 17:32 Werner Dworak Relationship added related to 0001097
2013-05-30 14:11 INOPIAE Relationship added related to 0001162
2013-07-09 20:52 INOPIAE Product Version => 2008
2013-07-09 22:37 Uli60 Note Added: 0004113
2013-07-09 22:38 Uli60 Note Edited: 0004113
2013-07-09 22:39 INOPIAE Note Added: 0004114
2013-07-09 22:39 INOPIAE Status new => closed
2013-07-09 22:39 INOPIAE Resolution open => fixed