security issues

Proxecto:Web
Componente:Main
Categoría:informe de erro
Prioridade:normal
Asignado:Sen asignar
Estado:closed
Descrición

A fellow on IRC (tomreyn) reported following:

you have an https://www.owasp.org/index.php/Open_redirect at http://trisquel.info/sites/countclick.php?url=http://microsoft.com

here's an xml injection: http://trisquel.info/sites/pfs.php?mime=%22%3E%0A%3C/RDF:Description%3E%0A%3CINJECTED%20injected=%22injected%22%3E%0A%3C/INJECTED%3E%0A%3CRDF:Description%20x=%22

Lun, 01/12/2015 - 00:07
Estado:active» fixed

Fixed both scripts.

Lun, 01/26/2015 - 00:10
Estado:fixed» closed

Automatically closed -- issue fixed for 2 weeks with no activity.