Report Regarding Security Vulnerability
T
Tor
Submitted None
Actions:
Reported by
srkfan
Vulnerability Details
Technical details and impact analysis
Hello Team,
i want to report a text injection and a misconfiguration of the 404 page
the bug exists at :
https://www.torproject.org/test/%2f../It%20has%20been%20changed%20by%20a%20new%20one%20https://www.Attacker.com%20so%20go%20to%20the%20new%20one%20since%20this%20one
as you can see attacker text is included
"It has been changed by a new one https://www.attacker.com so go to the new one since this one was not found on this server."
(Screenshot Attached)
Fix : just use a 404 page that don't include attacker text just as :a 404 page that don't include any external text
hope you fix it
thanks
Report Details
Additional information and metadata
State
Closed
Substate
Informative