Skip to content
This repository was archived by the owner on Oct 8, 2021. It is now read-only.

jQuery Mobile XSS Problem#1789

Closed
jnlin wants to merge 1 commit into
jquery-archive:masterfrom
jnlin:master
Closed

jQuery Mobile XSS Problem#1789
jnlin wants to merge 1 commit into
jquery-archive:masterfrom
jnlin:master

Conversation

@jnlin

@jnlin jnlin commented Jun 6, 2011

Copy link
Copy Markdown

Demo: http://jquerymobile.com/demos/1.0a4.1/#<img src=/ss onerror={alert('yy');}>

I am not sure if the patch is perfect, but it works for me.

@scottjehl

Copy link
Copy Markdown

Thanks! Looks like this is fixed in latest though, so I guess our navigation refactor covered it. Example here: http://jquerymobile.com/test/#<img src=/ss onerror={alert('yy');}>

Let me know if you still see the issue anywhere. Thanks!

@scottjehl scottjehl closed this Jun 9, 2011
@jnlin

jnlin commented Jun 14, 2011

Copy link
Copy Markdown
Author

It works, thank you :)

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants