PacketFence - BTS - PacketFence | |||||
| View Issue Details | |||||
| ID | Project | Category | View Status | Date Submitted | Last Update |
| 0001296 | PacketFence | security | public | 2011-10-03 12:25 | 2011-10-24 20:17 |
| Reporter | mattd | ||||
| Assigned To | obilodeau | ||||
| Priority | normal | Severity | major | Reproducibility | always |
| Status | closed | Resolution | fixed | ||
| Platform | OS | OS Version | |||
| Product Version | devel | ||||
| Target Version | 3.0.2 | Fixed in Version | 3.0.2 | ||
| fixed in git revision | |||||
| fixed in mtn revision | 92f9741dafd035ed1617b8ebb8d6a467cb0f1edb | ||||
| Summary | 0001296: XSS in captive portal web interface (several files) | ||||
| Description | In the following scripts of the captive portal web interface (html/captive-portal/): * guest-selfregistration.cgi * mobile-confirmation.cgi * redir.cgi * register.cgi ..the 'destination_url' parameter, passed in as an HTTP GET or POST parameter, is not escaped in script output, leading to XSS. | ||||
| Steps To Reproduce | |||||
| Additional Information | A sample request, triggering the XSS in register.cgi: register.cgi?mode=release&destination_url=%22%2balert%28document.cookie%29%2b%22 | ||||
| Tags | No tags attached. | ||||
| Relationships | |||||
| Attached Files | https://www.packetfence.org/bugs/file_download.php?file_id=113&type=bug | ||||
| Issue History | |||||
| Date Modified | Username | Field | Change | ||
| 2011-10-03 12:25 | mattd | New Issue | |||
| 2011-10-06 12:53 | obilodeau | Status | new => assigned | ||
| 2011-10-06 12:53 | obilodeau | Assigned To | => obilodeau | ||
| 2011-10-13 17:23 | obilodeau | File Added: security-fix-1296-destination-url-XSS.patch | |||
| 2011-10-13 17:35 | obilodeau | mtn revision | => 92f9741dafd035ed1617b8ebb8d6a467cb0f1edb | ||
| 2011-10-13 17:35 | obilodeau | Note Added: 0002345 | |||
| 2011-10-13 17:35 | obilodeau | Status | assigned => resolved | ||
| 2011-10-13 17:35 | obilodeau | Fixed in Version | => +1 | ||
| 2011-10-13 17:35 | obilodeau | Resolution | open => fixed | ||
| 2011-10-17 10:38 | obilodeau | Note Added: 0002363 | |||
| 2011-10-24 16:45 | obilodeau | View Status | private => public | ||
| 2011-10-24 20:15 | obilodeau | Target Version | => 3.0.2 | ||
| 2011-10-24 20:15 | obilodeau | Note Added: 0002392 | |||
| 2011-10-24 20:16 | obilodeau | Status | resolved => closed | ||
| 2011-10-24 20:17 | obilodeau | Fixed in Version | +1 => 3.0.2 | ||
| Notes | |||||
|
|
|||||
|
|
||||
|
|
|||||
|
|
||||
|
|
|||||
|
|
||||