Not signed in (Sign In)
  • Subscribe

    • Feed
    • CommentAuthorpablo77
    • CommentTimeJul 22nd 2010
     
    Some of my urls contains this string, for example:

    ui-bg_flat_75_ffffff_40x100.png - which is a part of jquery

    or

    filename-10x100px.jpg

    I have extracted from above examples, this string: -0x01, which is causing this issue.

    Any Ideas ?

    Logs:
    Total impact: 5<br/> Affected tags: id, rfe, xss<br/> <br/> Variable: REQUEST.4 | Value: ui-bg_flat_75_ffffff_40x100.png<br/> Impact: 5 | Tags: id, rfe, xss<br/> Description: Detects nullbytes and other dangerous characters | Tags: id, rfe, xss | ID: 39<br/> <br/>
    •  
      CommentAuthor.mario
    • CommentTimeAug 5th 2010
     
    Nice find! Fixed in the trunk - thanks a lot.
    • CommentAuthorpablo77
    • CommentTimeAug 9th 2010 edited
     
    It's always a pleasure to support you in building this superb project.