[wp-trac] Re: [WordPress Trac] #10226: Sanitization bypass in clean_url and wp_sanitise redirect

WordPress Trac wp-trac at lists.automattic.com
Sat Jun 20 18:41:27 GMT 2009


#10226: Sanitization bypass in clean_url and wp_sanitise redirect
--------------------------+-------------------------------------------------
 Reporter:  westi         |        Owner:  westi 
     Type:  defect (bug)  |       Status:  closed
 Priority:  normal        |    Milestone:  2.8.1 
Component:  Security      |      Version:  2.8   
 Severity:  normal        |   Resolution:  fixed 
 Keywords:                |  
--------------------------+-------------------------------------------------
Changes (by westi):

  * status:  reopened => closed
  * resolution:  => fixed


Comment:

 Replying to [comment:4 Denis-de-Bernardy]:
 > seems like there's a buggy loop, with one or both of:
 >
 >  - %0%0%0DAD
 >  - %0%0%0ADA

 Nope both of those are covered fine.

-- 
Ticket URL: <http://core.trac.wordpress.org/ticket/10226#comment:5>
WordPress Trac <http://core.trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list