[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2015-08-31 Thread angelwhu (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14724705#comment-14724705 ] angelwhu commented on WW-4507: -- Does it depend on the server ? i use tomcat 7, it doesn't work.

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2015-08-31 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14724852#comment-14724852 ] Lukasz Lenart commented on WW-4507: --- [~angelwhu] Which Struts version do you use? > Struts

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2015-08-31 Thread angelwhu (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14724863#comment-14724863 ] angelwhu commented on WW-4507: -- struts version is 2.3.16.3. page encode is utf-8. > Struts 2 XS

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2015-08-31 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14724867#comment-14724867 ] Lukasz Lenart commented on WW-4507: --- Looks like issue is related to container and proper en

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2015-09-08 Thread angelwhu (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14734348#comment-14734348 ] angelwhu commented on WW-4507: -- i use your environment . Application Server: JBoss-4.2.1.GA. Ja

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2015-10-08 Thread brian neisen (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14948986#comment-14948986 ] brian neisen commented on WW-4507: -- Hi, The problem is related to the page encoding. I w

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2015-10-08 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14949882#comment-14949882 ] Lukasz Lenart commented on WW-4507: --- Thanks [~greaser...@gmail.com] - will prepare an annou

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-01-05 Thread Rene Gielen (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15082735#comment-15082735 ] Rene Gielen commented on WW-4507: - I have tried to reproduce this with a page encoding of ISO

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-01-14 Thread ASF subversion and git services (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15098141#comment-15098141 ] ASF subversion and git services commented on WW-4507: - Commit 5421930b498

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-01-14 Thread ASF subversion and git services (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15098146#comment-15098146 ] ASF subversion and git services commented on WW-4507: - Commit 72471d70756

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-01-14 Thread ASF subversion and git services (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15098163#comment-15098163 ] ASF subversion and git services commented on WW-4507: - Commit a89bbe22cd2

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-01-14 Thread Hudson (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15098169#comment-15098169 ] Hudson commented on WW-4507: SUCCESS: Integrated in Struts-JDK6-support-2.3 #955 (See [https://b

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-01-14 Thread Hudson (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15098189#comment-15098189 ] Hudson commented on WW-4507: SUCCESS: Integrated in Struts-JDK7-master #404 (See [https://builds

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-01-14 Thread Rene Gielen (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15098308#comment-15098308 ] Rene Gielen commented on WW-4507: - We can confirm now that this is a platform issue. Especial

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-03-03 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15178248#comment-15178248 ] Lukasz Lenart commented on WW-4507: --- [~rgielen] is it done? > Struts 2 XSS vulnerability w

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-03-03 Thread Rene Gielen (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15178408#comment-15178408 ] Rene Gielen commented on WW-4507: - [~lukaszlenart] done, sorra for not resolving the issue >

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-03-03 Thread Lukasz Lenart (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15179365#comment-15179365 ] Lukasz Lenart commented on WW-4507: --- Great, thanks! > Struts 2 XSS vulnerability with > -

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-03-29 Thread Naozumi Taromaru (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15215689#comment-15215689 ] Naozumi Taromaru commented on WW-4507: -- I reproduced this issue. I use Struts 2.3.24.1 a

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-03-29 Thread victorsosa (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15215799#comment-15215799 ] victorsosa commented on WW-4507: Please check Rene comment > Struts 2 XSS vulnerability wit

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-03-29 Thread Naozumi Taromaru (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15217298#comment-15217298 ] Naozumi Taromaru commented on WW-4507: -- The analysis of Rene (14/Jan/16 16:04) is wrong.

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-03-30 Thread Rene Gielen (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15217656#comment-15217656 ] Rene Gielen commented on WW-4507: - [~taromaru] I'm not sure if my analysis above is completel

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-03-30 Thread Naozumi Taromaru (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15217857#comment-15217857 ] Naozumi Taromaru commented on WW-4507: -- > Historically we had many issues with solely re

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-04-03 Thread Naozumi Taromaru (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15223734#comment-15223734 ] Naozumi Taromaru commented on WW-4507: -- I created new issue. https://issues.apache.org/j

[jira] [Commented] (WW-4507) Struts 2 XSS vulnerability with

2016-07-15 Thread Hudson (JIRA)
[ https://issues.apache.org/jira/browse/WW-4507?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15379441#comment-15379441 ] Hudson commented on WW-4507: SUCCESS: Integrated in Struts-JDK7-master #495 (See [https://builds