Uploaded image for project: 'Struts 1'
  1. Struts 1
  2. STR-3191

Sufficently filter HTML tag attribute names and values

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Blocker
    • Resolution: Fixed
    • 1.2.9, 1.3.10
    • 1.4.0
    • Tag Libraries
    • None

    Description

      Allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to insufficient quoting of parameters.

      Attachments

        1. STR-3191-patch.txt
          8 kB
          Paul Benedict

        Activity

          People

            pbenedict Paul Benedict
            pbenedict Paul Benedict
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: