Uploaded image for project: 'Wicket'
  1. Wicket
  2. WICKET-3106

Security: Possible Redirection to foreign Page by using BrowserInfoPage's PageParameter

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Critical
    • Resolution: Fixed
    • 1.4.12
    • 1.4.13, 1.5-M3
    • wicket
    • None

    Description

      By link manipulation as a BookmarkableLink it is possible to redirect a User to foreign pages (probably without users notice).

      Example:

      http://wicketstuff.org/wicket14/compref/?wicket:bookmarkablePage=:org.apache.wicket.markup.html.pages.BrowserInfoPage&cto=http://www.google.de

      Reason:
      "Fallback"- Constructor in org.apache.wicket.markup.html.pages.BrowserInfoPage accepts every "cto" -PageParameter unevaluated regarding protocol prefex.

      Attachments

        Activity

          People

            ivaynberg Igor Vaynberg
            aul Thomas Aulinger
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - 2h
                2h
                Remaining:
                Remaining Estimate - 2h
                2h
                Logged:
                Time Spent - Not Specified
                Not Specified