Opened 16 years ago
Closed 16 years ago
#4244 closed Bug (fixed)
XSS in FCKeditor/trunk/_testcases/sampleposteddata.asp
| Reported by: | Paul Stone | Owned by: | |
|---|---|---|---|
| Priority: | Normal | Milestone: | FCKeditor 2.6.5 | 
| Component: | Server : ASP | Version: | |
| Keywords: | Cc: | 
Description
The sForm variable is outputted unescaped, allowing XSS. The versions of sampleposteddata.asp in the samples directory were updated a few weeks ago, but it looks like this one was missed
Change History (2)
comment:1 Changed 16 years ago by
| Milestone: | → FCKeditor 2.6.5 | 
|---|
comment:2 Changed 16 years ago by
| Resolution: | → fixed | 
|---|---|
| Status: | new → closed | 
