Koha/koha-tmpl/intranet-tmpl/prog/en/modules/serials
Chris d87b8a5cf3 Bug 14423: Multiple XSS vulnerabilities in serials-search
To test

1/ Hit a url like http://localhost:8081/cgi-bin/koha/serials/serials-search.pl?bookseller_filter=%22%22%22%3E%3Cscript%3Ealert%28%27oh%20noes%27%29%3C/script%3E&searched=1&title_filter=
2/ Notice alert boxes
3/ Apply patch
4/ Reload, notice fixed

Repeat for
callnumber_filter
EAN_filter
ISSN_filter
publisher_filter
title_filter

Signed-off-by: Jonathan Druart <jonathan.druart@koha-community.org>

Signed-off-by: Katrin Fischer <katrin.fischer.83@web.de>
Signed-off-by: Tomas Cohen Arazi <tomascohen@theke.io>
2015-06-23 10:12:26 -03:00
..
tables
acqui-search-result.tt
acqui-search.tt
checkexpiration.tt
claims.tt
result.tt
routing-preview-slip.tt
routing-preview.tt
routing.tt
serial-issues-full.tt
serial-issues.tt
serials-collection.tt Bug 13662: Fix the serials.receive_serials permissions 2015-06-05 12:53:09 -03:00
serials-edit.tt Bug 13423: Remove unused JS function in serials-edit.tt 2015-05-14 11:48:17 -03:00
serials-home.tt
serials-search.tt Bug 14423: Multiple XSS vulnerabilities in serials-search 2015-06-23 10:12:26 -03:00
showpredictionpattern.tt
subscription-add.tt Bug 9139: New subscription form - Does not check form on the first page 2015-05-14 11:42:35 -03:00
subscription-bib-search.tt
subscription-detail.tt
subscription-frequencies.tt
subscription-history.tt
subscription-numberpatterns.tt
subscription-renew.tt
viewalerts.tt