Uploaded image for project: 'Bug Archive'
  1. Bug Archive
  2. BUGARCHIVE-6603

WRD error screen vulnerable to malicious XSS attack (javascript code injection)

    XMLWordPrintable

    Details

    • Type: Maintenance
    • Status: Fixed (View Workflow)
    • Resolution: Unresolved
    • Labels:
      None
    • Old bug number:
      28459
    • Patch version:
      O309,P207

      Description

      Using certain URL's causes the 'yellow error screen' of the WRD to be
      vulnerable to a cross-site scripting (XSS) attack. That might cause arbitrary
      Javascript to be executed.

        Attachments