[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
[tor-bugs] #23574 [Internal Services/Tor Sysadmin Team]: Don't allow text injection in our 404 page
#23574: Don't allow text injection in our 404 page
-----------------------------------------------------+-----------------
Reporter: gk | Owner: tpa
Type: defect | Status: new
Priority: Medium | Milestone:
Component: Internal Services/Tor Sysadmin Team | Version:
Severity: Normal | Keywords:
Actual Points: | Parent ID:
Points: | Reviewer:
Sponsor: |
-----------------------------------------------------+-----------------
We got a report on HackerOne by sumitthehacker:
{{{
i want to report a text injection and a misconfiguration of the 404 page
the bug exists at :
https://www.torproject.org/test/%2f../It%20has%20been%20changed%20by%20a%20new%20one%20https://www.Attacker.com%20so%20go%20to%20the%20new%20one%20since%20this%20one
as you can see attacker text is included
"It has been changed by a new one https://www.attacker.com so go to the
new one since this one was not found on this server."
}}}
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/23574>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs