Page 1 of 1
XSS message on reuters.com
Posted: Thu May 09, 2013 3:27 am
by ThatITguy
Any article on reuters.com seems to produce an XSS error.
Steps to reproduce:
Either click on a Reuters new story in Google News or go directly to an article on reuters.com
(IE:
http://www.reuters.com/article/2013/05/ ... 3020130509 ).
Re: XSS message on reuters.com
Posted: Thu May 09, 2013 3:30 am
by ThatITguy
Relevant Console Log:
Code: Select all
[NoScript XSS] Sanitized suspicious request. Original URL [http://tags.bluekai.com/site/4972?ret=html&phint=cnt%3DText&phint=cc%3DhealthNews&phint=pn%3D1&phint=pt%3D1&phint=rch%3DNews&phint=rco%3DBETAUS&phint=wcntn%3DNews%20-%20Health&phint=wcnts%3DhealthNews&phint=z0%3Dus.reuters&phint=z1%3Dnews&phint=z2%3Dhealth&phint=z3%3Darticle&phint=wtc%3D23b7cf76c02ed1dfa201364191833719&phint=log%3Dnull&phint=soc%3D&phint=hsh%3Dnull&phint=ref%3D&phint=sea%3D&phint=__bk_t%3DWrigley%20halts%20production%20of%20caffeine%20gum%20following%20FDA%20concern%20%7C%20Reuters&phint=__bk_k%3DCasey%20Keller&phint=__bk_l%3Dhttp%3A%2F%2Fwww.reuters.com%2Farticle%2F2013%2F05%2F09%2Fus-wrigley-caffeine-idUSBRE94803020130509&limit=10&r=30777510] requested from [http://www.reuters.com/article/2013/05/09/us-wrigley-caffeine-idUSBRE94803020130509]. Sanitized URL: [http://tags.bluekai.com/site/4972?ret=html&phint=cnt%20Text&phint=cc%20healthNews&phint=pn%201&phint=pt%201&phint=rch%20News&phint=rco%20BETAUS&phint=wcntn%20News%20-%20Health&phint=wcnts%20healthNews&phint=z0%20us.reuters&phint=z1%20news&phint=z2%20health&phint=z3%20article&phint=wtc%2023b7cf76c02ed1dfa201364191833719&phint=log%20null&phint=soc%20&phint=hsh%20null&phint=ref%20&phint=sea%20&phint=__bk_t%20Wrigley%20halts%20production%20of%20caffeine%20gum%20following%20FDA%20concern%20%7C%20Reuters&phint=__bk_k%20Casey%20Keller&phint=__bk_l%20http%3A%2F%2Fwww.reuters.com%2Farticle%2F2013%2F05%2F09%2Fus-wrigley-caffeine-idUSBRE94803020130509&limit=10&r=30777510#7575505125444566973].
Re: XSS message on reuters.com
Posted: Thu May 09, 2013 7:18 am
by Giorgio Maone
Is there any reason for bluekay.com to be in your whitelist (i.e. does the main site break if you forbid it)?
Anyway, I'll try to work-around this false positive in next release.