Summary | XSS via X-color |
Queue | IMP |
Queue Version | 4.1 |
Type | Bug |
State | Resolved |
Priority | 1. Low |
Owners | |
Requester | miksir (at) maker (dot) ru |
Created | 04/10/2006 (7075 days ago) |
Due | |
Updated | 04/10/2006 (7075 days ago) |
Assigned | |
Resolved | 04/10/2006 (7075 days ago) |
Github Issue Link | |
Github Pull Request | |
Milestone | |
Patch | No |
State ⇒ Resolved
State ⇒ Unconfirmed
Priority ⇒ 1. Low
Type ⇒ Bug
Summary ⇒ XSS via X-color
Queue ⇒ IMP
X-Color field may be created by remote client .
For example:
X-color: "><!--a75c305b1c0a6022--><script>alert("hello");</script><"