Download
Getting Started
Members
Projects
Community
Marketplace
Events
Planet Eclipse
Newsletter
Videos
Participate
Report a Bug
Forums
Mailing Lists
Wiki
IRC
How to Contribute
Working Groups
Automotive
Internet of Things
LocationTech
Long-Term Support
PolarSys
Science
OpenMDM
More
Community
Marketplace
Events
Planet Eclipse
Newsletter
Videos
Participate
Report a Bug
Forums
Mailing Lists
Wiki
IRC
How to Contribute
Working Groups
Automotive
Internet of Things
LocationTech
Long-Term Support
PolarSys
Science
OpenMDM
Toggle navigation
Bugzilla – Attachment 213496 Details for
Bug 375751
[Help] Security vulnerabilities in deferredView.jsp
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Requests
|
Help
|
Log In
[x]
|
Terms of Use
|
Copyright Agent
Some Eclipse Foundation services are deprecated, or will be soon. Please ensure you've read
this important communication.
[patch]
Fix with updated copyright
patch2.txt (text/plain), 1.18 KB, created by
Chris Austin
on 2012-04-03 09:43:00 EDT
(
hide
)
Description:
Fix with updated copyright
Filename:
MIME Type:
Creator:
Chris Austin
Created:
2012-04-03 09:43:00 EDT
Size:
1.18 KB
patch
obsolete
>diff --git a/org.eclipse.help.webapp/advanced/deferredView.jsp b/org.eclipse.help.webapp/advanced/deferredView.jsp >index 6a7a1e0..f30777c 100644 >--- a/org.eclipse.help.webapp/advanced/deferredView.jsp >+++ b/org.eclipse.help.webapp/advanced/deferredView.jsp >@@ -1,5 +1,5 @@ > <%-- >- Copyright (c) 2006, 2010 IBM Corporation and others. >+ Copyright (c) 2006, 2012 IBM Corporation and others. > All rights reserved. This program and the accompanying materials > are made available under the terms of the Eclipse Public License v1.0 > which accompanies this distribution, and is available at >@@ -13,6 +13,11 @@ > <% > RequestData data = new RequestData(application, request, response); > WebappPreferences prefs = data.getPrefs(); >+ >+ String baseURL = request.getRequestURL().toString(); >+ baseURL = baseURL.substring(0,baseURL.lastIndexOf("/")+1); >+ >+ String href = baseURL+request.getParameter("href"); > %> > > <html lang="<%=ServletResources.getString("locale", request)%>"> >@@ -22,7 +27,7 @@ > > <script language="JavaScript"> > function onloadHandler() { >- location.href="<%=UrlUtil.JavaScriptEncode(request.getParameter("href"))%>"; >+ location.href="<%=UrlUtil.JavaScriptEncode(href)%>"; > } > </script> >
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Flags:
daniel_megert
:
review+
Actions:
View
|
Diff
Attachments on
bug 375751
:
213402
| 213496