Message4080
...and the fact that Roundup is passing arbitrary HTML in the URL for this case being submitted
isn't great either, as it has the exact same problem. (Potentially worse, since this one allows
arbitrary injection on a normal, non-error page)
http://issues.roundup-tracker.org/issue2550654?
@ok_message=msg%204079%20created%3Cbr%3Eissue%202550654%20created&@template=ite
m |
|
Date |
User |
Action |
Args |
2010-06-30 14:39:43 | benjamin | set | messageid: <1277908783.89.0.230140766719.issue2550654@psf.upfronthosting.co.za> |
2010-06-30 14:39:43 | benjamin | set | recipients:
+ benjamin |
2010-06-30 14:39:43 | benjamin | link | issue2550654 messages |
2010-06-30 14:39:43 | benjamin | create | |
|