XSS false positive?

Ask for help about NoScript, no registration needed to post
barbaz
Senior Member
Posts: 11142
Joined: Sat Aug 03, 2013 5:45 pm

XSS false positive?

Post by barbaz »

SeaMonkey 2.36pre (based on Firefox 39.0.3), NoScript 2.6.9.35rc2

Code: Select all

[NoScript InjectionChecker] JavaScript Injection in ///?q=print+centos+6.6
(function anonymous() {
q=print+centos+6.6 /* COMMENT_TERMINATOR */
DUMMY_EXPR
})

[NoScript XSS] Sanitized suspicious request. Original URL [https://duckduckgo.com/?q=print+centos+6.6] requested from [chrome://navigator/content/navigator.xul]. Sanitized URL: [https://duckduckgo.com/?q=PRINT+centos+6.6#6397655835664119625].
*Always* check the changelogs BEFORE updating that important software!
-