Red Hat Bugzilla – Bug 451032
Syndication page - update_uri field
Last modified: 2008-10-06 12:34:59 EDT
Description of problem: XXS able to add property to DOM, this page is very
Version-Release number of selected component (if applicable):
Steps to Reproduce:
1. Log into: https://propaganda-wpmu-mt.usersys.redhat.com/wordpress-mu/wp-admin/
2. Logged in as admin
3. Clicked the Syndication link
4. Run the XXS automated testing tool test all forms top attacks
Actual results: Test had errors, able to add property to DOM, this page is very
Expected results: Test passed.
Created attachment 309073 [details]
Automated Test Failure Information
The update_uri field value ended up on the page unescaped. Changed the plugin
code so it is printed after passing through htmlspecialchars().
Code is now up on blogs.corp.redhat.com
Moving to product "Red Hat Collaboration Applications".