security issues

Project:Web
Component:Main
Category:bug report
Priority:normal
Assigned:Unassigned
Status:closed
Description

A fellow on IRC (tomreyn) reported following:

you have an https://www.owasp.org/index.php/Open_redirect at http://trisquel.info/sites/countclick.php?url=http://microsoft.com

here's an xml injection: http://trisquel.info/sites/pfs.php?mime=%22%3E%0A%3C/RDF:Description%3E%0A%3CINJECTED%20injected=%22injected%22%3E%0A%3C/INJECTED%3E%0A%3CRDF:Description%20x=%22

Sun, 01/11/2015 - 23:07
Status:active» fixed

Fixed both scripts.

Sun, 01/25/2015 - 23:10
Status:fixed» closed

Automatically closed -- issue fixed for 2 weeks with no activity.