Download
Getting Started
Members
Projects
Community
Marketplace
Events
Planet Eclipse
Newsletter
Videos
Participate
Report a Bug
Forums
Mailing Lists
Wiki
IRC
How to Contribute
Working Groups
Automotive
Internet of Things
LocationTech
Long-Term Support
PolarSys
Science
OpenMDM
More
Community
Marketplace
Events
Planet Eclipse
Newsletter
Videos
Participate
Report a Bug
Forums
Mailing Lists
Wiki
IRC
How to Contribute
Working Groups
Automotive
Internet of Things
LocationTech
Long-Term Support
PolarSys
Science
OpenMDM
Toggle navigation
Bugzilla – Attachment 183492 Details for
Bug 330026
[Webapp][Security] Fix for Eclipse 3.6.2 Eclipse Help Server XSS
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Requests
|
Help
|
Log In
[x]
|
Terms of Use
|
Copyright Agent
[patch]
Patch version 2 including fix for endless loop in script in toolbar.jsp
patch330026b.txt (text/plain), 3.34 KB, created by
Chris Goldthorpe
on 2010-11-19 13:15:17 EST
(
hide
)
Description:
Patch version 2 including fix for endless loop in script in toolbar.jsp
Filename:
MIME Type:
Creator:
Chris Goldthorpe
Created:
2010-11-19 13:15:17 EST
Size:
3.34 KB
patch
obsolete
>### Eclipse Workspace Patch 1.0 >#P org.eclipse.help.webapp >Index: advanced/content.jsp >=================================================================== >RCS file: /cvsroot/eclipse/org.eclipse.help.webapp/advanced/content.jsp,v >retrieving revision 1.33 >diff -u -r1.33 content.jsp >--- advanced/content.jsp 21 Apr 2010 18:00:16 -0000 1.33 >+++ advanced/content.jsp 19 Nov 2010 18:13:32 -0000 >@@ -45,7 +45,7 @@ > > </head> > <frameset id="contentFrameset" rows="<%=frameData.getContentAreaFrameSizes()%>" frameborder=0" framespacing="0" border="0" spacing="0"> >- <frame name="ContentToolbarFrame" title="<%=ServletResources.getString("topicViewToolbar", request)%>" src='<%="contentToolbar.jsp"+data.getQuery()%>' marginwidth="0" marginheight="0" scrolling="no" frameborder="0" > >+ <frame name="ContentToolbarFrame" title="<%=ServletResources.getString("topicViewToolbar", request)%>" src='<%="contentToolbar.jsp"+UrlUtil.htmlEncode(data.getQuery())%>' marginwidth="0" marginheight="0" scrolling="no" frameborder="0" > > <frame ACCESSKEY="K" name="ContentViewFrame" title="<%=ServletResources.getString("topicView", request)%>" src='<%=UrlUtil.htmlEncode(data.getContentURL())%>' marginwidth="10"<%=(data.isIE() && "6.0".compareTo(data.getIEVersion()) <=0)?"scrolling=\"yes\"":""%> marginheight="0" frameborder="0" > > <% > AbstractFrame[] frames = frameData.getFrames(AbstractFrame.BELOW_CONTENT); >Index: advanced/toolbar.jsp >=================================================================== >RCS file: /cvsroot/eclipse/org.eclipse.help.webapp/advanced/toolbar.jsp,v >retrieving revision 1.64 >diff -u -r1.64 toolbar.jsp >--- advanced/toolbar.jsp 21 Apr 2010 18:00:16 -0000 1.64 >+++ advanced/toolbar.jsp 19 Nov 2010 18:13:32 -0000 >@@ -196,8 +196,12 @@ > function registerMaximizedChangedListener(){ > // get to the frameset > var p = parent; >- while (p && !p.registerMaximizeListener) >+ while (p && !p.registerMaximizeListener) { >+ if (p === p.parent) { >+ return; >+ } > p = p.parent; >+ } > > if (p!= null){ > p.registerMaximizeListener('<%=UrlUtil.JavaScriptEncode(data.getName())%>Toolbar', maximizedChanged); >Index: basic/index.jsp >=================================================================== >RCS file: /cvsroot/eclipse/org.eclipse.help.webapp/basic/index.jsp,v >retrieving revision 1.17 >diff -u -r1.17 index.jsp >--- basic/index.jsp 21 Apr 2010 18:00:17 -0000 1.17 >+++ basic/index.jsp 19 Nov 2010 18:13:32 -0000 >@@ -29,8 +29,8 @@ > <% > } > %> >- <frame name="TabsFrame" title="<%=ServletResources.getString("helpToolbarFrame", request)%>" src='<%="basic/tabs.jsp"+data.getQuery()%>' marginwidth="5" marginheight="5" scrolling="no"> >- <frame name="HelpFrame" title="<%=ServletResources.getString("ignore", "HelpFrame", request)%>" src='<%="basic/help.jsp"+data.getQuery()%>' frameborder="no" marginwidth="0" marginheight="0" scrolling="no"> >+ <frame name="TabsFrame" title="<%=ServletResources.getString("helpToolbarFrame", request)%>" src='<%="basic/tabs.jsp"+UrlUtil.htmlEncode(data.getQuery())%>' marginwidth="5" marginheight="5" scrolling="no"> >+ <frame name="HelpFrame" title="<%=ServletResources.getString("ignore", "HelpFrame", request)%>" src='<%="basic/help.jsp"+UrlUtil.htmlEncode(data.getQuery())%>' frameborder="no" marginwidth="0" marginheight="0" scrolling="no"> > <% > if(!("0".equals(data.getFooterHeight()))){ > %>
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Actions:
View
|
Diff
Attachments on
bug 330026
:
182922
|
183492
|
183586