http://www.wolflair.com/frame.php?context=army_builder&url=javascript:alert(/openbugbounty/)
Reported by
lacroute...@gmail.com,
Dec 20 2017
|
||||
Issue descriptionDevice name: sony aqua m with this url http://www.wolflair.com/frame.php?context=army_builder&url=javascript:alert(/openbugbounty/) popup show on android webphone with chrome i have discovered bypass xss in chrome chrome for my android webphone android 5.0 kernel 3.10.49-perf-gc6d4e64 numero du build 26.1.B.3.109 Actual result: popup show
,
Dec 21 2017
Tested the issue in Android and could not reproduce the issue Steps Followed: 1. Launched the Chrome Browser. 2. Navigate to http://www.wolflair.com/frame.php?context=army_builder&url=javascript:alert(/openbugbounty/) 3. Page doesn't load (Observing white screen) Chrome versions tested 63.0.3239.111(Stable) Android 4.4.4 Android Devices: 4.4.4; C6902 Build/14.4.A.108 @lacroutelacroute: Could you please help us with the accessible URL, and chrome version on which your'e facing the issue. Thanks!!
,
Dec 21 2017
the page has been corrected by the care of its webmaster it's too late
,
Dec 21 2017
Thank you for providing more feedback. Adding requester "sandeepkumars@chromium.org" to the cc list and removing "Needs-Feedback" label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Dec 21 2017
this url work http://topsea.co.il/frame.php?url=javascript:alert(/OPENBUGBOUNTY/) http://komokaweather.com/weather28/canada/frame.php?width=800px&url=javascript:alert(/OPENBUGBOUNTY/) http://ladner-bc.ca/weather2/canada/frame.php?width=800px&url=javascript:alert(/openbugbounty/) http://www3.ntnu.edu.tw/frame.php?url=javascript:alert(/OPENBUGBOUNTY/) http://cryptonewsology.com/frame.php?url=javascript:alert(/openbugbounty/)
,
Dec 22 2017
Tested the issue in Android and able to reproduce the issue. Observed the Pop up message Steps Followed: 1. Launched the Chrome Browser. 2. Navigate to http://topsea.co.il/frame.php?url=javascript:alert(/OPENBUGBOUNTY/) 3. Observed the Pop up message Chrome versions tested 63.0.3239.111(Stable) Android 4.4.4 Android Devices: 4.4.4; C6902 Build/14.4.A.108 This seems to be a Non-Regression issue as same behavior is seen since M62. Untriaged for further input's on this issue. Please navigate to below link for log's and video-- go/chrome-androidlogs/796540 Note: This issue is observed using #63.0.3239.108 in Desktop (Win, Mac and Linux) as well Thanks!!
,
Dec 29 2017
Issue 796877 has been merged into this issue. |
||||
►
Sign in to add a comment |
||||
Comment 1 by pnangunoori@chromium.org
, Dec 21 2017