Some Eclipse Foundation services are deprecated, or will be soon. Please ensure you've read this important communication.
Bug 355865 - JAX-RPC sample generator still vulnerable to cross site scripting (XSS)
Summary: JAX-RPC sample generator still vulnerable to cross site scripting (XSS)
Status: RESOLVED FIXED
Alias: None
Product: WTP Webservices
Classification: WebTools
Component: jst.ws (show other bugs)
Version: unspecified   Edit
Hardware: PC All
: P3 normal (vote)
Target Milestone: 3.2.5   Edit
Assignee: Ivan Castro CLA
QA Contact: Keith Chong CLA
URL:
Whiteboard:
Keywords:
Depends on:
Blocks: 356089 356091
  Show dependency tree
 
Reported: 2011-08-25 11:42 EDT by Ivan Castro CLA
Modified: 2011-08-29 12:33 EDT (History)
0 users

See Also:


Attachments
Fix patch (1.33 KB, patch)
2011-08-25 12:23 EDT, Ivan Castro CLA
keith.chong.ca: iplog+
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Ivan Castro CLA 2011-08-25 11:42:57 EDT
Build Identifier: 3.2.4

We are returning the exceptions java traces which includes the parameters passed through the sample. If the parameter includes any javascript it will be run in the client when we return the exception.

Reproducible: Always
Comment 1 Ivan Castro CLA 2011-08-25 12:23:24 EDT
Created attachment 202164 [details]
Fix patch
Comment 2 Keith Chong CLA 2011-08-29 12:33:44 EDT
Released for 3.2.5.