Comment 3 for bug 740142

Revision history for this message
John A Meinel (jameinel) wrote : Re: [Bug 740142] Re: persistent xss vector in (unescaped) filenames in revision views

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 3/22/2011 1:14 PM, daveb wrote:
> new example at
> http://bazaar.launchpad.net/~daveb/+junk/delete_me_v2/revision/2?start_revid=2
>

I certainly get a popup box on loading that page.

 status: triaged
 importance: critical

John
=:->

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (Cygwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAk2IquMACgkQJdeBCYSNAAPvtACguNrSFZ4esKjfCt5nTuqFF1D/
+6IAn23CkQ3FJzLYUqC998e29Y96YEEY
=0UCC
-----END PGP SIGNATURE-----