[Bug 9754] Possible XSS exploit possibility

wine-bugs at winehq.org wine-bugs at winehq.org
Tue Oct 16 21:42:41 CDT 2007


http://bugs.winehq.org/show_bug.cgi?id=9754


Chris Morgan <cmorgan at alum.wpi.edu> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |cmorgan at alum.wpi.edu




--- Comment #2 from Chris Morgan <cmorgan at alum.wpi.edu>  2007-10-16 21:42:41 ---
(In reply to comment #1)
> Even after #9755 got fixed and I get the error message "Insufficient
> privileges", I am still able to change the title via sTitle in the URL.
> 


The title is generated upon page refresh using the information in the url. As
far as I can tell you are only changing the title that you see on the page. I'm
not sure that this presents a security concern.

Chris


-- 
Configure bugmail: http://bugs.winehq.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are watching all bug changes.



More information about the wine-bugs mailing list