Re: XSS in search form at git-scm.com

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi Anton,

Bugs for git-scm.com are tracked on GitHub, please file your issue at
https://github.com/github/gitscm-next/issues.

-- 
Paul Betts <paul@xxxxxxxxxxxxx>

On Fri, May 11, 2012 at 5:28 AM, Anton <forshr@xxxxxxxxx> wrote:
> Hello.
>
> Search form at git-scm.com is vulnerable to XSS.
>
> Short link
>
> bit.ly/KQ2Tcd
> http://bit.ly/K7VvJM
>
> Real links
> alert
> http://git-scm.com/search/results?search=%3Cscript%3Ealert('privet%20Lambda%20:peka:%20_/')%3C/script%3E
> Google logo
> http://bit.ly/K7VvJM
> --
> To unsubscribe from this list: send the line "unsubscribe git" in
> the body of a message to majordomo@xxxxxxxxxxxxxxx
> More majordomo info at  http://vger.kernel.org/majordomo-info.html
--
To unsubscribe from this list: send the line "unsubscribe git" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


[Index of Archives]     [Linux Kernel Development]     [Gcc Help]     [IETF Annouce]     [DCCP]     [Netdev]     [Networking]     [Security]     [V4L]     [Bugtraq]     [Yosemite]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Linux SCSI]     [Fedora Users]