Cross Site Scripting at TorProject Blog
GET parameter incorrectly filter GET query which allows attackers to execute JavaScript code which is called Cross Site Scripting.
https://blog.torproject.org/archive/1%3Cbody%20onload=alert%28666%29%3E/2013/11/,
Trac:
Username: patryk.bogdan@pentesters.pl
- Show closed items
Activity
-
Newest first Oldest first
-
Show all activity Show comments only Show history only
the blog seems to run a very, very old version of drupal. maybe step one is to upgrade the blog. or scrap it for a modern blog platform.
Trac:
Status: new to assigned
Owner: Patryk Bogdan to phobosTrac:
Status: assigned to newTrac:
Owner: phobos to N/A
Status: new to assignedTrac:
Status: assigned to newTrac:
Username: mastertlionTrac:
Username: mastertlionTrac:
Username: mastertlionMoving to new Blog component
Trac:
Component: Website to Blogthe new blog went online, I guess this is fixed now, otherwise please reopen.
Trac:
Resolution: N/A to fixed
Reviewer: N/A to N/A
Status: new to closed- Trac closed
closed