Page 1 of 1
Firefox 4.0.1 & NoScript 2.1.0.3 -> critical bug in forms!
Posted: Mon May 09, 2011 2:03 pm
by Perlover
Hi!
I traced that NoScript (Firefox 4.0.1 & NoScript 2.1.0.3) has a seriously bug with HTML forms - some form fields of other reloaded forms are set in previous reloaded data of same structred forms!
Some selects, textarea's values can be setup to incorrect values from previous reloadings!
In source for example i have: <select name="example1"><option value="example2">example2</option><option value="example3" selected>example3</option></seclect>
But i see example2 selected for example. If i turn off NoScript and reload Firefox - all forms are worked correctly
I cannot give my example - this is intranet corporate statistic
May be this bug occurs only in frame structures - i see it in my frame statistic - from one frame i click by link for loading form into other frame and i see not correctly setup fields!
This is 100% bug of NoScript - i tested more times - with NoScript some form fields are set in values as in previous reloaded same-structure filled forms!
Same bug affects to textarea value's for example!The new loaded textarea's window has a previous loaded data from other form!
This is the very seriously bug - many people can lose a submited data of forms
I have lost data because i submitted not properly selected data and textarea's values already

((
I am needed to turnoff your plugin

Re: Firefox 4.0.1 & NoScript 2.1.0.3 -> bug in forms
Posted: Mon May 09, 2011 5:20 pm
by njak
I have this bug too, it appears if you visit several URL's first and try then use page where you have some input elements to play.
After submit old submitted values are filled to forms, if change values, it still send those old values! 2.1.0.4rc5 still have this security and annoying bug.
Re: Firefox 4.0.1 & NoScript 2.1.0.3 -> bug in forms
Posted: Mon May 09, 2011 5:26 pm
by njak
njak wrote:I have this bug too, it appears if you visit several URL's first and try then use page where you have some input elements to play.
After submit old submitted values are filled to forms, if change values, it still send those old values! 2.1.0.4rc5 still have this security and annoying bug.
More note to this, i have intranet and iframe on page too, where this pug comes. Autocomplete is turned on in firefox options and html don't have autocomplete tag.
Re: Firefox 4.0.1 & NoScript 2.1.0.3 -> bug in forms
Posted: Tue May 10, 2011 2:58 pm
by Perlover
And i tested now my 'buggy' pages where i saw bug but now i have Firefox 3.6.16 & NoScript 2.1.0.3 - there no bug
So bug is only in Firefox v. 4.0 and more
And when i told 'intranet' i meant a closed from public statistics. Intranet here not other type of internet of course
Re: Firefox 4.0.1 & NoScript 2.1.0.3 -> critical bug in form
Posted: Tue May 10, 2011 3:06 pm
by Giorgio Maone
Unfortunately I cannot check it until you show me a public accessible web page where this happens consistently

Re: Firefox 4.0.1 & NoScript 2.1.0.3 -> critical bug in form
Posted: Wed May 11, 2011 1:16 pm
by Haven Hospice Admin
I have Firefox 4.0.1 and NoScript,
I also have the same problem described-
Open a webpage we use to edit users' voicemail. The current settings are displayed in a form. I can make changes if I wish.
When I open a second user's settings, some of the fields have been changed to be the previous user's data.
Then I open a third user, some of the fields show the first user's data, some of the fields show the second user's data, and some of the fields are correct for the third user.
Re: Firefox 4.0.1 & NoScript 2.1.0.3 -> critical bug in form
Posted: Wed May 11, 2011 1:22 pm
by Giorgio Maone
Is there any webpage I can access in order to reproduce this issue?
Re: Firefox 4.0.1 & NoScript 2.1.0.3 -> critical bug in form
Posted: Thu May 12, 2011 4:41 pm
by Perlover
Sorry, but i cannot give you access - my statistics protocted by IP of VPN point.
I should ask my www administrator to remove it option temporary.
But if you will get an access - there 50% of text in Russian language (you will see many unknown characters and there will be difficult my description what you should do for reproduce of bug)
May be anyone will give you access for reproducing this bug and with English interface? For example, may be will "Haven Hospice Admin" help?
Sorry, i am glad to help you. If i will find a same frame's forms pages everywhere i will give you URL for testing.
Re: Firefox 4.0.1 & NoScript 2.1.0.3 -> critical bug in form
Posted: Thu May 19, 2011 6:03 am
by Guest
This Firefox bug was maybe related to this problem.
https://bugzilla.mozilla.org/show_bug.cgi?id=628043
With latest 6.0a1 and NoScript 2.1.0.5rc2 is good now, I haven't tested with Firefox 4 there error maybe still occurs.
Re: Firefox 4.0.1 & NoScript 2.1.0.3 -> critical bug in form
Posted: Fri Jun 03, 2011 8:24 pm
by Perlover
Good day, Giorgio!
Now i decided to test version 2.1.1
Before today i didn't use NoScript since 2.1.0.3.
Now i don't see the bug.
Giorgio, did you fix this bug or this bug was fixed itself?
Now yet i am afraid to use NoScript as far as because i am not sure fixed bug exactly or it rarely occurs now.
If there is bug i can lose a data after editing though form submitting process ;-/
Re: Firefox 4.0.1 & NoScript 2.1.0.3 -> critical bug in form
Posted: Fri Jun 03, 2011 8:33 pm
by Perlover
Now and before i have FF 4.0.1
This bug fixed but in FF 5.x as i understood
So may be this bug is not that bug
Re: Firefox 4.0.1 & NoScript 2.1.0.3 -> critical bug in form
Posted: Fri Jun 03, 2011 8:40 pm
by Perlover
njak and Haven Hospice Admin, can you test this bug again with NoScript 2.1.1 & FF 4.0.1?
If you will not find a bug again it will be good news
Thanks
Re: Firefox 4.0.1 & NoScript 2.1.0.3 -> critical bug in form
Posted: Fri Jun 03, 2011 10:32 pm
by therube
(If I'm reading the bug 628043 correctly, appears it will never be fixed in FF 4.)
Re: Firefox 4.0.1 & NoScript 2.1.0.3 -> critical bug in form
Posted: Sat Jun 04, 2011 2:34 pm
by dhouwn
Naturally, since Mozilla does not plan on releasing 4.0.2 (but maybe some software repository maintainers will backport this fix).