Erling Ellingsen
48e0cf8479
Don't send URL in redirect body
...
If you put a CR in the redirect URL, the response splitting protection refuses to send the Location header, and the body is rendered in the browser; instant xss. It would not surprise me if some browsers ignore the Location header for less obviously broken URLs, so let's just remove the URL entirely.
2013-04-25 00:49:58 -07:00
..
2013-04-22 14:43:49 -07:00
2013-04-22 14:43:49 -07:00
2013-04-23 09:52:58 -07:00
2013-04-25 00:49:58 -07:00
2013-04-22 14:43:49 -07:00
2013-04-23 12:57:40 -07:00
2013-04-22 14:43:49 -07:00
2013-04-22 14:43:49 -07:00
2013-04-22 14:43:49 -07:00
2013-04-22 14:43:49 -07:00
2013-02-19 06:57:54 -08:00
2013-04-22 14:43:49 -07:00
2013-04-18 13:54:55 -07:00
2013-03-27 16:52:16 -07:00
2013-02-11 02:10:41 -08:00
2013-04-22 14:43:49 -07:00
2013-04-18 12:19:05 -07:00
2013-04-22 14:43:49 -07:00
2013-03-09 12:49:37 -08:00
2013-04-22 14:43:49 -07:00
2013-03-09 10:25:16 -08:00
2013-04-22 14:43:49 -07:00
2013-03-08 17:52:20 -08:00
2013-04-22 14:43:49 -07:00
2013-03-18 15:12:16 -07:00
2013-02-11 02:10:41 -08:00
2013-03-09 10:25:16 -08:00
2013-04-22 14:43:49 -07:00
2013-04-23 12:57:40 -07:00
2013-04-22 14:43:49 -07:00
2013-04-22 14:43:49 -07:00
2013-04-23 12:57:40 -07:00
2013-03-09 10:25:16 -08:00
2013-03-08 17:52:20 -08:00
2013-04-22 14:43:49 -07:00
2013-03-09 15:07:37 -08:00
2013-04-22 14:43:49 -07:00
2013-04-22 14:43:49 -07:00
2013-03-09 10:25:16 -08:00
2013-04-22 14:43:49 -07:00
2013-03-09 12:49:37 -08:00
2013-04-22 14:43:49 -07:00
2013-02-11 02:10:41 -08:00
2013-04-22 14:43:49 -07:00
2013-04-22 14:43:49 -07:00
2013-02-11 02:10:41 -08:00
2013-04-22 14:43:49 -07:00
2013-04-17 08:54:58 -07:00
2013-04-22 14:43:49 -07:00
2013-04-12 12:04:04 -07:00
2013-04-22 14:43:50 -07:00
2013-04-25 00:49:50 -07:00
2013-04-25 00:49:50 -07:00
2013-04-01 11:51:31 -07:00
2013-04-22 14:43:49 -07:00
2013-03-08 08:50:45 -08:00
2013-04-22 14:43:49 -07:00
2013-04-01 13:46:30 -07:00
2013-04-22 14:43:49 -07:00
2013-04-18 13:54:55 -07:00
2013-04-22 14:43:49 -07:00
2013-04-22 14:43:49 -07:00
2013-02-19 06:57:54 -08:00
2013-04-22 14:43:49 -07:00
2013-04-24 12:42:45 -07:00
2013-04-22 14:43:49 -07:00
2013-02-11 02:10:41 -08:00
2013-04-22 14:43:49 -07:00
2013-03-27 16:10:33 -07:00
2013-04-22 14:43:49 -07:00
2013-04-22 14:43:49 -07:00
2013-04-23 09:52:57 -07:00
2013-03-07 16:19:03 -08:00
2013-04-22 14:43:49 -07:00
2013-03-09 12:49:37 -08:00
2013-04-22 14:43:49 -07:00
2013-04-02 15:01:37 -07:00
2013-04-22 14:43:49 -07:00
2013-04-23 12:59:00 -07:00
2013-04-23 12:59:00 -07:00
2013-02-11 02:10:41 -08:00
2013-04-22 14:43:49 -07:00
2013-04-01 11:51:31 -07:00
2013-04-23 09:52:58 -07:00
2013-04-18 13:55:38 -07:00
2013-04-23 09:52:58 -07:00
2013-04-23 09:52:58 -07:00
2013-04-23 12:59:00 -07:00
2013-04-23 09:52:57 -07:00
2013-04-04 12:20:04 -07:00
2013-04-22 14:43:49 -07:00
2013-04-18 13:54:55 -07:00
2013-04-22 14:43:49 -07:00