<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cross Site Scripting Attacks in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/cross-site-scripting-attacks/m-p/215366#M168496</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;If you've found a reproducible bug, the correct place to log it is JIRA (see the link in my signature below).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Mike&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 28 Apr 2010 10:53:54 GMT</pubDate>
    <dc:creator>mikeh</dc:creator>
    <dc:date>2010-04-28T10:53:54Z</dc:date>
    <item>
      <title>Cross Site Scripting Attacks</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/cross-site-scripting-attacks/m-p/215365#M168495</link>
      <description>Hi,We need to get approval for Security team before application be rolled out. When we sought approval, they concluded Alfresco Share is prone to Cross Site Scripting Attacks…I need help to overcome this issue and get the things going..Ver: Alfresco 3.3 Browser: IE7..Thanks in Advance</description>
      <pubDate>Wed, 28 Apr 2010 10:49:38 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/cross-site-scripting-attacks/m-p/215365#M168495</guid>
      <dc:creator>ahamed_rasmi</dc:creator>
      <dc:date>2010-04-28T10:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cross Site Scripting Attacks</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/cross-site-scripting-attacks/m-p/215366#M168496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;If you've found a reproducible bug, the correct place to log it is JIRA (see the link in my signature below).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Mike&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Apr 2010 10:53:54 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/cross-site-scripting-attacks/m-p/215366#M168496</guid>
      <dc:creator>mikeh</dc:creator>
      <dc:date>2010-04-28T10:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cross Site Scripting Attacks</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/cross-site-scripting-attacks/m-p/215367#M168497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I posted in JIRA.. It was accepted.. But not accessible..&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;May i know the reason mike..? ALF-2623 is the code.. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Ahamed Rasmi&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Apr 2010 08:49:21 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/cross-site-scripting-attacks/m-p/215367#M168497</guid>
      <dc:creator>ahamed_rasmi</dc:creator>
      <dc:date>2010-04-29T08:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cross Site Scripting Attacks</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/cross-site-scripting-attacks/m-p/215368#M168498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Generally, if an XSS or similar security issue has been identified and is reproducible, we set the JIRA issue to be accessible by Alfresco staff only - that way it's not "Googleable".&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Mike&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Apr 2010 21:04:34 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/cross-site-scripting-attacks/m-p/215368#M168498</guid>
      <dc:creator>mikeh</dc:creator>
      <dc:date>2010-04-29T21:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cross Site Scripting Attacks</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/cross-site-scripting-attacks/m-p/215369#M168499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Ok.. then how would i know about the status… and possible solutions..&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Do you think UrlRewrite way with regex would solve this issue?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Ahamed&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Apr 2010 04:09:41 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/cross-site-scripting-attacks/m-p/215369#M168499</guid>
      <dc:creator>ahamed_rasmi</dc:creator>
      <dc:date>2010-04-30T04:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cross Site Scripting Attacks</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/cross-site-scripting-attacks/m-p/215370#M168500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I have fixed the issue.. now share site is safe.. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Added a Filter.. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In filter replaced the uri parameter letters like &amp;lt;,&amp;gt; into different letters.. So script tag is not executed..&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Issue considered as closed..&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Ahamed&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Apr 2010 08:56:57 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/cross-site-scripting-attacks/m-p/215370#M168500</guid>
      <dc:creator>ahamed_rasmi</dc:creator>
      <dc:date>2010-04-30T08:56:57Z</dc:date>
    </item>
  </channel>
</rss>

