View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0002048 | OXID eShop (all versions) | 4.04. Security | public | 2010-08-17 16:16 | 2010-08-24 11:31 |
| Reporter | sarunas_valaskevicius | Assigned To | |||
| Priority | immediate | Severity | major | Reproducibility | always |
| Status | resolved | Resolution | fixed | ||
| Target Version | 4.4.2 revision 29492 | Fixed in Version | 4.4.2 revision 29492 | ||
| Summary | 0002048: xss in admin login page | ||||
| Description | on user login error or cookies error exception thrown, entered (GET or POST) user and passwd are outputed unescaped. The problem in admin/login.php checklogin() For more details check the security bulletin: http://wiki.oxidforge.org/Security_bulletins/2010-003 | ||||
| Tags | No tags attached. | ||||
| Theme | |||||
| Browser | All | ||||
| PHP Version | any | ||||
| Database Version | any | ||||