Bug#652587: libhtml-template-pro-perl: missing escaping allows XSS

2011-12-19 Thread Moritz Mühlenhoff
On Mon, Dec 19, 2011 at 07:47:52PM +0100, Ansgar Burchardt wrote: > Ansgar Burchardt writes: > > The JS escaping in libhtml-template-pro-perl misses to escape "<" and > > ">" which allows XSS. This was fixed in the last upstream release (0.9507). > > > > An example script that triggers the bug is

Bug#652587: libhtml-template-pro-perl: missing escaping allows XSS

2011-12-19 Thread Ansgar Burchardt
Ansgar Burchardt writes: > The JS escaping in libhtml-template-pro-perl misses to escape "<" and > ">" which allows XSS. This was fixed in the last upstream release (0.9507). > > An example script that triggers the bug is attached. With 0.9507 it > outputs > > > > older versions generat

Bug#652587: libhtml-template-pro-perl: missing escaping allows XSS

2011-12-18 Thread Ansgar Burchardt
> An example script that triggers the bug is attached. With 0.9507 it > outputs > > > > older versions generate > > > > instead. This time for real. #! /usr/bin/perl use strict; use warnings; my $var = ''; my $tmpl = < EOT use HTML::Template::Pro; my $t = HTML::Template::Pro->new(

Bug#652587: libhtml-template-pro-perl: missing escaping allows XSS

2011-12-18 Thread Ansgar Burchardt
Package: libhtml-template-pro-perl Version: 0.9502-1 Severity: important Tags: security The JS escaping in libhtml-template-pro-perl misses to escape "<" and ">" which allows XSS. This was fixed in the last upstream release (0.9507). An example script that triggers the bug is attached. With 0.9