History | Log In     View a printable version of the current page.  
Issue Details (XML | Word | Printable)

Key: DOTCMS-2917
Type: Bug Bug
Status: Released Released
Resolution: Released
Priority: Major Major
Assignee: Testing User
Reporter: Jason Tesser
Watchers: 0
Operations

If you were logged in you would be able to see more operations.
dotCMS

XSS Fix in dotCMS is Encoding at times we don't want

Created: July 13, 2009 11:16 AM   Updated: July 23, 2009 11:55 AM  Due: 8/12/08
Component/s: a. Unknown
Affects Version/s: None
Fix Version/s: 1.9

Time Tracking:
Original Estimate: 1 hour
Original Estimate - 1 hour
Remaining Estimate: 1 hour
Remaining Estimate - 1 hour
Time Spent: Not Specified
Remaining Estimate - 1 hour

Issue Links:
Cloners
 


 Description  « Hide
We need to wrap the request and stick it in the VelocityContext so that we can override getParameter and encode the XSS there.

 All   Comments   Work Log   Change History   Subversion Commits   FishEye      Sort Order: Ascending order - Click to sort in descending order
There are no comments yet on this issue.