View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
0002048 | OXID eShop (all versions) | 4.04. Security | public | 2010-08-17 16:16 | 2010-08-24 11:31 |
Reporter | sarunas_valaskevicius | Assigned To | |||
Priority | immediate | Severity | major | Reproducibility | always |
Status | resolved | Resolution | fixed | ||
Target Version | 4.4.2 revision 29492 | Fixed in Version | 4.4.2 revision 29492 | ||
Summary | 0002048: xss in admin login page | ||||
Description | on user login error or cookies error exception thrown, entered (GET or POST) user and passwd are outputed unescaped. The problem in admin/login.php checklogin() For more details check the security bulletin: http://wiki.oxidforge.org/Security_bulletins/2010-003 | ||||
Tags | No tags attached. | ||||
Theme | |||||
Browser | All | ||||
PHP Version | any | ||||
Database Version | any | ||||