Issue metadata
Sign in to add a comment
|
Security: XSS protection allows for disabling of JavaScript
Reported by
giel.sni...@gmail.com,
May 17 2016
|
||||||||||||||||||
Issue descriptionVULNERABILITY DETAILS Chromium checks for JavaScript from the URI reflected in the source code, to prevent Cross Site Scripting. This allows an attacker to modify the requested page by disabling genuine JavaScript features on the page. VERSION Chrome Version: tested on 49.0.2623.112 but vulnerability probably exists on most versions Operating System: Windows 7 SP1 REPRODUCTION CASE Open attached .html file and open with following parameters: test.html?x=%09<script>%0D%0A%09%09alert(1)%3B%0D%0A%09%09alert(2)%3B%0D%0A%09%09<%2Fscript> Notice that only the third alert triggers, due to the first two being disabled by the browser.
,
Aug 24 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 1 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
|
|||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||
Comment 1 by tsepez@chromium.org
, May 17 2016