Details
Description
A cross-site scripting attack is possible through the error message.
Activity
| Repository | Revision | Date | User | Message |
| ICEsoft Public SVN Repository | #14890 | Thu Oct 04 16:11:30 MDT 2007 | ted.goddard | Error messages echoed to the browser should not contain user input ( |
| Files Changed | ||||
MODIFY
/icefaces/trunk/icefaces/core/src/com/icesoft/faces/webapp/http/servlet/PathDispatcher.java
|
| Field | Original Value | New Value |
|---|---|---|
| Security | Private [ 10001 ] |
| Assignee | Mircea Toma [ mircea.toma ] |
| Fix Version/s | 1.7DR#2 [ 10110 ] |
| Status | Open [ 1 ] | Resolved [ 5 ] |
| Resolution | Fixed [ 1 ] |
| Fix Version/s | 1.6.2 [ 10111 ] | |
| Assignee | Mircea Toma [ mircea.toma ] | Ted Goddard [ ted.goddard ] |
| Resolution | Fixed [ 1 ] | |
| Status | Resolved [ 5 ] | Reopened [ 4 ] |
| Repository | Revision | Date | User | Message |
| ICEsoft Public SVN Repository | #15022 | Wed Oct 24 16:55:06 MDT 2007 | ted.goddard | Error messages echoed to the browser should not contain user input ( |
| Files Changed | ||||
MODIFY
/icefaces/branches/icefaces-1.6/icefaces/core/src/com/icesoft/faces/webapp/http/servlet/PathDispatcher.java
|
| Status | Reopened [ 4 ] | Resolved [ 5 ] |
| Resolution | Fixed [ 1 ] |
| Fix Version/s | 1.7 [ 10080 ] |
| Status | Resolved [ 5 ] | Closed [ 6 ] |
| Assignee | Ted Goddard [ ted.goddard ] |
| Resolution | Fixed [ 1 ] | |
| Status | Closed [ 6 ] | Reopened [ 4 ] |
| Security | Private [ 10001 ] |
| Status | Reopened [ 4 ] | Resolved [ 5 ] |
| Resolution | Fixed [ 1 ] |
| Status | Resolved [ 5 ] | Closed [ 6 ] |

svn merge -r 13642:14890 ../../../trunk/icefaces/core/src/com/icesoft/faces/webapp/http/servlet/PathDispatcher.java core/src/com/icesoft/faces/webapp/http/servlet/PathDispatcher.java