Skip to content

Conversation

@mehulmpt
Copy link
Contributor

Visit this page before updating the website:

http://oscarotero.com/embed2/demo/index.php?url=%3Cimg%20src=x%20onerror=alert()%3E%20%3Ch1%20style=%22position:absolute;top:0;font-size:100px%22%3EThis%20is%20easily%20defaceable

It shows a message This is easily defaceable. If you disable your inbuilt XSS auditor, (ex-run in firefox), you can even execute arbitrary javascript on the frontend.
I've fixed that by checking if URL is actually a URL or not.

oscarotero added a commit that referenced this pull request Nov 26, 2015
Parsed down the URL parameter which earlier allowed XSS on page
@oscarotero oscarotero merged commit df96135 into php-embed:master Nov 26, 2015
@oscarotero
Copy link
Collaborator

Good job. Thank you!

@mehulmpt
Copy link
Contributor Author

:)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants