New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.
Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Last visit > 30 days ago
Closed: Sep 2010
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 3
Type: Bug-Security
M-7

Restricted
  • Only users with EditIssue permission may comment.



Sign in to add a comment
link

Issue 53002: pop blocker bypass

Reported by kuz...@gmail.com, Aug 22 2010

Issue description

tested chromium

testcase.htm
============
<base target="some"> 
<script>
history.go()
</script>
 

Comment 1 by infe...@chromium.org, Aug 22 2010

Labels: -Pri-0 -Area-Undefined Pri-3 Area-Internals SecSeverity-Low OS-All
Status: Available
It does bypass the popup blocker on both v5 stable and v6 trunk. However, i dont think it can open more than one tab.

Johnny, can you please take a look when you get time.

Comment 2 by jnd@chromium.org, Sep 7 2010

will start to investigate and update more details tomorrow.

Comment 3 by jnd@chromium.org, Sep 8 2010

done investigation, filed a bug on https://bugs.webkit.org/show_bug.cgi?id=45369

Comment 4 by infe...@chromium.org, Sep 16 2010

Labels: Mstone-7

Comment 5 by infe...@chromium.org, Sep 17 2010

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Status: WillMerge
Awesome Johnny, you knocked another popup blocker bug. :)

Committed r67716: <http://trac.webkit.org/changeset/67716>. Needs to be merged to 517.

Comment 6 by infe...@chromium.org, Sep 24 2010

Status: FixUnreleased
Merged in r68305.

Comment 7 by jsc...@chromium.org, Mar 21 2011

Labels: Type-Security

Comment 8 by jsc...@chromium.org, Oct 5 2011

Labels: SecImpacts-Stable
Batch update.

Comment 9 by jsc...@chromium.org, Apr 18 2012

Labels: -Restrict-View-SecurityNotify
Lifting view restrictions.

Comment 10 by jsc...@chromium.org, Apr 18 2012

Status: Fixed

Comment 11 by bugdroid1@chromium.org, Oct 13 2012

Project Member
Labels: Restrict-AddIssueComment-Commit
This issue has been closed for some time. No one will pay attention to new comments.
If you are seeing this bug or have new data, please click New Issue to start a new bug.

Comment 12 by bugdroid1@chromium.org, Mar 10 2013

Project Member
Labels: -Area-Internals -SecSeverity-Low -Mstone-7 -Type-Security -SecImpacts-Stable Security-Severity-Low Security-Impact-Stable M-7 Cr-Internals Type-Bug-Security

Comment 13 by bugdroid1@chromium.org, Mar 13 2013

Project Member
Labels: -Restrict-AddIssueComment-Commit Restrict-AddIssueComment-EditIssue

Comment 14 by bugdroid1@chromium.org, Mar 21 2013

Project Member
Labels: -Security-Severity-Low Security_Severity-Low

Comment 15 by bugdroid1@chromium.org, Mar 21 2013

Project Member
Labels: -Security-Impact-Stable Security_Impact-Stable

Comment 16 by sheriffbot@chromium.org, Oct 1 2016

Project Member
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 17 by sheriffbot@chromium.org, Oct 2 2016

Project Member
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 18 by mbarbe...@chromium.org, Oct 2 2016

Labels: allpublic

Sign in to add a comment