OpenSocial / spec

OpenSocial Specification #social
http://opensocial.org/
Apache License 2.0
106 stars 11 forks source link

[BUG XSS TYPEWRITTER]xss-javascript code in typewritter #427

Closed mmarum-sugarcrm closed 11 years ago

mmarum-sugarcrm commented 11 years ago

Original author: arph...@gmail.com (May 15, 2008 15:16:22)

Description of the bug/feature ==================================

profiles using xss code in typewritter/name alert-prompt in use in typewritter/name example of the script in use:script>alert('Lol')</script>

http://www.orkut.com/Profile.aspx?uid=6828975275399546776 http://www.orkut.com/Profile.aspx?uid=12535950420433109569 http://www.orkut.com/Profile.aspx?uid=1653397792325311671 http://www.orkut.com/Profile.aspx?uid=7364362485557228390 http://www.orkut.com/Profile.aspx?uid=13589293559681889131 http://www.orkut.com/Profile.aspx?uid=12865972278775917511 http://www.orkut.com/Profile.aspx?uid=7148688597467885316 http://www.orkut.com/Profile.aspx?uid=15081226744246150035 http://www.orkut.com/Profile.aspx?uid=9112559295442069791 http://www.orkut.com/Profile.aspx?uid=14073181731404878043 http://www.orkut.com/Profile.aspx?uid=17010493176546840745 http://www.orkut.com/Profile.aspx?uid=15097062012341682713 http://www.orkut.com/Profile.aspx?uid=1630915517237564220 http://www.orkut.com/Profile.aspx?uid=8214442479929001387

and other profiles thanks

Original issue: http://code.google.com/p/opensocial-resources/issues/detail?id=177

mmarum-sugarcrm commented 11 years ago

From arph...@gmail.com on May 15, 2008 17:32:32 sorry TYPERACER

mmarum-sugarcrm commented 11 years ago

_From apirohi...@gtempaccount.com on May 30, 2008 21:07:24 Hi, It looks like this issue is fixed now. In case, you see it again, please get back to us.

Thanks, The OpenSocial Team

mmarum-sugarcrm commented 11 years ago

From arph...@gmail.com on June 01, 2008 02:30:24 Thanks for your attention