Quantcast
Channel: SCN : All Content - SAP Enterprise Portal
Viewing all articles
Browse latest Browse all 3876

Cross Scripting(Xss) Vulnerability Check to Logon Module

$
0
0

Hi Experts,

 

Please let me know and suggest with any example, if any of you applied and solved Xss Vulnerability Check to Login Page of SAP EP Portal.

 

Below example shows for customized portal application.

 

https://scn.sap.com/community/enterprise-portal/blog/2014/10/07/an-approach-to-web-security-issues-on-customized-portal-applications

 

I am checking for login page of portal , i.e passing of this type of javascript values to parameters

 

https://<host>:<port>/irj/portal?j_username=Test&"onmouseover="location.href='https://www.google.com'"

 

shouldnot work, even on setting "Disable" value for Enable XSS Filter in Internet Explorer(IE) browser settings under security tab.


Viewing all articles
Browse latest Browse all 3876

Trending Articles