for. See bug 389128. git-svn-id: svn://10.0.0.236/trunk@238361 18797224-902f-48f8-a5cc-f745e15eee43
31 lines
2.1 KiB
HTML
31 lines
2.1 KiB
HTML
<h2>test form w/ messed up data</h2>
|
|
<form action="/service/" method="post">
|
|
<div><input name="v" value="0.3"/></div>
|
|
<div><input name="rmoVers" value="0.3"/></div>
|
|
<div><input name="url" value="http://mozila.org/page"/></div>
|
|
<div><input name="problem_type" value="2"/></div>
|
|
<div><input name="description" value=")(*!@)(*)!(*@#///''''aa900907/<script>alert('foobarbq');</script>"/></div>
|
|
<div><input name="behind_login" value="0"/></div>
|
|
<div><input name="platform" value=")(*!@)(*)!(*@#///''''aa900907/<script>alert('foobarbq');</script>"/></div>
|
|
<div><input name="oscpu" value=")(*!@)(*)!(*@#///''''aa900907/<script>alert('foobarbq');</script>"/></div>
|
|
<div><input name="gecko" value=")(*!@)(*)!(*@#///''''aa900907/<script>alert('foobarbq');</script>"/></div>
|
|
<div><input name="product" value=")(*!@)(*)!(*@#///''''aa900907/<script>alert('foobarbq');</script>"/></div>
|
|
<div><input name="useragent" value=")(*!@)(*)!(*@#///''''aa900907/<script>alert('foobarbq');</script>"/></div>
|
|
<div><input name="buildconfig" value=")(*!@)(*)!(*@#///''''aa900907/<script>alert('foobarbq');</script>"/></div>
|
|
<div><input name="language" value=")(*!@)(*)!(*@#///''''aa900907/<script>alert('foobarbq');</script>"/></div>
|
|
<div><input name="email" value=")(*!@)(*)!(*@#///''''aa900907/<script>alert('foobarbq');</script>"/></div>
|
|
<div><input name="sysid" value="win"/></div>
|
|
<div><input name="screenshot" value=")(*!@)(*)!(*@#///''''aa900907/<script>alert('foobarbq');</script>"/></div>
|
|
<div><input name="screenshot_format" value=")(*!@)(*)!(*@#///''''aa900907/<script>alert('foobarbq');</script>"/></div>
|
|
<div><input name="charset" value="utf-8"/></div>
|
|
<div><input name="screenshot" value=")(*!@)(*)!(*@#///''''aa900907/<script>alert('foobarbq');</script>"/></div>
|
|
<div><input name="screenshot_format" value="image/png"/></div>
|
|
<div><input name="charset" value=")(*!@)(*)!(*@#///''''aa900907/<script>alert('foobarbq');</script>"/></div>
|
|
<div><input name="language" value="en-US"/></div>
|
|
<div><input name="method" value="submitReport"/></div>
|
|
<div><input type="submit" value="submit"/></div>
|
|
</form>
|
|
|
|
<h2>sql for test above to work</h2>
|
|
insert into sysid values ('win',now(),'127.0.0.1','en');
|