Menu

#2391 (ok 2.10.1) XSS in PMA_sanitize()

2.10.0.2
fixed
1
2013-06-11
2007-03-13
No

PMA_sanitize() does not remove JavaScript from links

Discussion

  • Sebastian Mendel

    patch file, should work for all versions since 2.9

     
  • Sebastian Mendel

    • status: open --> open-fixed
     
  • Sebastian Mendel

    Logged In: YES
    user_id=326580
    Originator: YES

    File Added: pma_sanitize_xss.patch

     
  • Sebastian Mendel

    • priority: 9 --> 1
    • summary: XSS in PMA_sanitize() --> (ok 2.10.0.3) XSS in PMA_sanitize()
     
  • Sebastian Mendel

    Logged In: YES
    user_id=326580
    Originator: YES

    thanks for reporting to sp3x SecurityReasons

     
  • Marc Delisle

    Marc Delisle - 2007-04-17

    Logged In: YES
    user_id=210714
    Originator: NO

    File Added: pma_sanitize_xss2.patch

     
  • Marc Delisle

    Marc Delisle - 2007-04-17

    latest patch for 2.10.0.2

     
  • Marc Delisle

    Marc Delisle - 2007-04-28
    • summary: (ok 2.10.0.3) XSS in PMA_sanitize() --> (ok 2.10.1) XSS in PMA_sanitize()
     
  • Marc Delisle

    Marc Delisle - 2007-04-28
    • status: open-fixed --> closed-fixed
     
  • Michal Čihař

    Michal Čihař - 2013-06-11
    • Status: closed-fixed --> fixed