Some Eclipse Foundation services are deprecated, or will be soon. Please ensure you've read this important communication.

Bug 356089

Summary: JAX-RPC sample generator still vulnerable to cross site scripting (XSS)
Product: [WebTools] WTP Webservices Reporter: Keith Chong <keith.chong.ca>
Component: jst.wsAssignee: Ivan Castro <ivanc>
Status: RESOLVED FIXED QA Contact: Keith Chong <keith.chong.ca>
Severity: normal    
Priority: P3 CC: ivanc
Version: unspecified   
Target Milestone: 3.4 M2   
Hardware: PC   
OS: All   
Whiteboard:
Bug Depends on: 355865, 356091    
Bug Blocks:    

Description Keith Chong CLA 2011-08-29 10:50:47 EDT
+++ This bug was initially created as a clone of Bug #355865 +++

Build Identifier: 3.2.4

We are returning the exceptions java traces which includes the parameters passed through the sample. If the parameter includes any javascript it will be run in the client when we return the exception.

Reproducible: Always

For HEAD stream. (3.4)
Comment 1 Keith Chong CLA 2011-09-01 00:57:30 EDT
Released to 3.4 (HEAD)