Menu

#2 href="javascript:..." is a security proble

v2.37
open-accepted
Keilaron
Security (1)
1
2005-03-19
2003-03-06
No

remove any a tags that have javascript: at the start of
the href.

Discussion

  • Brett Taylor

    Brett Taylor - 2003-03-07
    • assigned_to: nobody --> glutnix
    • summary: href="javascript:..." is a security problem --> href="javascript:..." is a security problem
     
  • Keilaron

    Keilaron - 2005-03-19
    • summary: href="javascript:..." is a security problem --> href="javascript:..." is a security proble
    • labels: --> Security
    • assigned_to: glutnix --> nobody
     
  • Keilaron

    Keilaron - 2005-03-19

    Logged In: YES
    user_id=1049905

    I think this got fixed even before 2.33 ... you're talking
    about the URL textbox, right?

     
  • Keilaron

    Keilaron - 2005-03-19
    • priority: 5 --> 1
    • milestone: --> v2.37
    • assigned_to: nobody --> keilaron
    • status: open --> open-accepted
     
  • Keilaron

    Keilaron - 2005-03-19

    Logged In: YES
    user_id=1049905

    This was fixed in 2.33, but the fix just changes the URL
    rather than rejecting it or removing it. I think I'll change
    that.

     

Log in to post a comment.

Want the latest updates on software, tech news, and AI?
Get latest updates about software, tech news, and AI from SourceForge directly in your inbox once a month.