Commits on Jan 23, 2013
@dregad dregad Fix #15415: XSS vulnerability on Configuration Report page
A project name containing javascript code results in execution of said
code when displaying the filter's project list.

Note that despite using the same function to display the option list,
the vulnerability does not exist for usernames (due to input
restrictions in place when creating/updating user accounts) or config
names (which must exist in config_default_inc.php and must be valid php
@dregad dregad Fix #15416: XSS issue in adm_config_report.php
If a 'complex' config option contains javascript code, it would be
executed when displaying the page.
Showing with 2 additions and 2 deletions.
  1. +2 −2 adm_config_report.php
4 adm_config_report.php
@@ -87,7 +87,7 @@ function print_config_value_as_string( $p_type, $p_value, $p_for_display = true
if( $p_for_display ) {
- echo "<pre>$t_output</pre>";
+ echo '<pre>' . string_attribute( $t_output ) . '</pre>';
} else {
echo $t_output;
@@ -97,7 +97,7 @@ function print_option_list_from_array( $p_array, $p_filter_value ) {
foreach( $p_array as $t_key => $t_value ) {
echo "<option value='$t_key'";
check_selected( $p_filter_value, $t_key );
- echo ">$t_value</option>\n";
+ echo ">" . string_attribute( $t_value ) . "</option>\n";

