Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

suspicion of double encoding in referrer field - prob. false alarm #44

Closed
GoogleCodeExporter opened this issue May 20, 2015 · 4 comments

Comments

@GoogleCodeExporter
Copy link

What steps will reproduce the problem?
1.Create a HTTP Request where the referrer field holds a URL with an
ampersand (&) for parameters.
2.
3.

What is the expected output? What do you see instead?
referrer field with amperstand should be legit.
Instead, ESAPI finds it as a double encoding hacking attach.

What version of the product are you using? On what operating system?
1.4 on Unix

Please provide any additional information below.


Original issue reported on code.google.com by nada...@gmail.com on 25 Oct 2009 at 1:10

@GoogleCodeExporter
Copy link
Author

Need to check if this is still the case in 2.0 - If so it can be resolved there 
and
will vote on whether to release a patch to 1.4 to resolve the issue there.

Original comment by chrisisbeef on 29 Oct 2009 at 5:15

  • Added labels: Component-Logic

@GoogleCodeExporter
Copy link
Author

Additional information here would be helpful. Can you include a code sample that
illustrates your issue?

Original comment by chrisisbeef on 2 Dec 2009 at 7:29

@GoogleCodeExporter
Copy link
Author

We already addresses this in the latest enhancements to cannonicalization. I'm 
dropping this unless someone brings this up again.

Original comment by manico.james@gmail.com on 1 Nov 2010 at 6:00

  • Changed state: Fixed

@GoogleCodeExporter
Copy link
Author

drop +1

Original comment by chrisisbeef on 1 Nov 2010 at 7:13

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant