What steps will reproduce the problem?
1. Input such as <%00script>alert(1)</script>
2.
3.
What is the expected output? What do you see instead?
Remove the null byte, then validate as normal. Instead, the tag goes through
untouched. A tag formatted in this manner will be interpreted as a valid script
tag in IE (tested on IE8) but not on any other major browser to my knowledge.
What version of the product are you using? On what operating system?
Latest, Java on Linux
Please provide any additional information below.
Original issue reported on code.google.com by krpata...@gmail.com on 9 Dec 2011 at 3:34
Original issue reported on code.google.com by
krpata...@gmail.com
on 9 Dec 2011 at 3:34