General

Profile

Markus Bucher

Issues

open closed Total
Assigned issues 0 0 0
Reported issues 0 5 5

Activity

2015-07-01

16:20 TYPO3 Core Revision 7695d91f: [SECURITY] XSS in Filelist
Properly escape user input when showing error messages
during file renaming.
Resolves: #59211
Releases: master, 6.2
...
Markus Bucher
16:17 TYPO3 Core Revision 128d2412: [SECURITY] XSS in Filelist
Properly escape user input when showing error messages
during file renaming.
Resolves: #59211
Releases: master, 6.2
...
Markus Bucher
16:09 TYPO3 Core Revision 6fa4c8e3: [SECURITY] XSS in Filelist
Properly escape user input when showing error messages
during file renaming.
Resolves: #59211
Releases: master, 6.2
...
Markus Bucher

2014-05-29

11:20 TYPO3 Core Bug #59199 (Closed): Element Browser: GET-Data is not unencoded in fields
The wizard browser takes it's set values out of a GET param. It fails to decode these params.
In the link field of...
Markus Bucher

2012-08-15

12:22 TYPO3 Core Revision 25186002: [SECURITY] XSS in validateForm
Properly quote the form name and field list
for the JavaScript validation
Fixes: #25052
Releases: 6.0, 4.7, 4.6, 4.5...
Markus Bucher
12:20 TYPO3 Core Revision a1c3165e: [SECURITY] Page Link Target vulnerable to XSS
This patch adds htmlspecialchars to page link target to prevent
XSS.
Change-Id: Iadf524cebd03428fad1880f25c1698fba41...
Markus Bucher
12:20 TYPO3 Core Revision 8cf7db71: [SECURITY] XSS in validateForm
Properly quote the form name and field list
for the JavaScript validation
Fixes: #25052
Releases: 6.0, 4.7, 4.6, 4.5...
Markus Bucher
12:19 TYPO3 Core Revision 2ae69c8a: [SECURITY] Page Link Target vulnerable to XSS
This patch adds htmlspecialchars to page link target to prevent
XSS.
Change-Id: I9e1ab1ac22c7bc1225f1d3d3234865e1e60...
Markus Bucher
12:19 TYPO3 Core Revision 1eaebd38: [SECURITY] XSS in validateForm
Properly quote the form name and field list
for the JavaScript validation
Fixes: #25052
Releases: 6.0, 4.7, 4.6, 4.5...
Markus Bucher
12:18 TYPO3 Core Revision 85df0e45: [SECURITY] Page Link Target vulnerable to XSS
This patch adds htmlspecialchars to page link target to prevent
XSS.
Change-Id: Ib8f812f89f892f580fc70300a4e4fa22875...
Markus Bucher

Also available in: Atom