View Issue Details

IDProjectCategoryView StatusLast Update
0000805Main CAcert Websitesource codepublic2013-01-15 14:31
Reporteraphexer Assigned To 
PrioritynormalSeverityminorReproducibilityalways
Status closedResolutionopen 
Fixed in Version2010 Q1 
Summary0000805: unescaped html entities in output of account.php
DescriptionIf a user has special characters (like an '&') in his "lost passphrase questions" then these are not properly escaped and hence misinterpreted by the webbrowser.

In pages/account/13.php on lines 135-154, please use htmlentities() on the value to be output.

Note: only checked this in 5 minutes, didn't test it ;)
TagsNo tags attached.
Reviewed by
Test Instructions

Activities

Sourcerer

2010-01-17 14:11

administrator   ~0001555

Thanks a lot, Bug has been fixed.

NEOatNHNG

2012-05-30 21:17

administrator   ~0003030

Closing issues that have been resolved more than one year ago…

Issue History

Date Modified Username Field Change
2010-01-17 11:44 aphexer New Issue
2010-01-17 14:11 Sourcerer Note Added: 0001555
2010-01-17 14:11 Sourcerer Status new => solved?
2012-05-30 21:17 NEOatNHNG Note Added: 0003030
2012-05-30 21:17 NEOatNHNG Status solved? => closed
2013-01-15 14:31 Werner Dworak Fixed in Version => 2010 Q1