Archiva

Cannot delete patterns with single and double quotes.

Details

  • Number of attachments :
    0

Description

Add/edit Proxy Connector:

  • Blacklist: cannot delete patterns with ' and "
  • whitelist: cannot delete patterns with '

Repository Scanning:

  • cannot delete patterns with ' and "

Activity

Hide
Brett Porter added a comment -

This is a (very obscure) way to inject some code, for example: 1', ''); alert('XSS'); setAndSubmit('pattern', '1

Show
Brett Porter added a comment - This is a (very obscure) way to inject some code, for example: 1', ''); alert('XSS'); setAndSubmit('pattern', '1
Hide
Olivier Lamy added a comment -

more an escape javascript issue

Show
Olivier Lamy added a comment - more an escape javascript issue
Hide
Olivier Lamy added a comment -

fixed r1178794 and r1178795

Show
Olivier Lamy added a comment - fixed r1178794 and r1178795

People

Vote (0)
Watch (0)

Dates

  • Created:
    Updated:
    Resolved: