SAP Knowledge Base Article - Preview

1907818 - HTML code in txt file gets executed in KM

Symptom

In KM content you upload some .txt files which contains some html code. You clicked on the .txt file, hoping to see its content as text. But the txt is parsed as html.
In extreme situations, txt with malicious html code can be executed unexpectedly.


Read more...

Environment

  • Release Independent
  • Internet Explorer (up to IE11)

Product

SAP NetWeaver 7.0 ; SAP NetWeaver 7.3 ; SAP NetWeaver 7.4 ; SAP NetWeaver 7.5 ; SAP enhancement package 1 for SAP NetWeaver 7.0 ; SAP enhancement package 1 for SAP NetWeaver 7.3 ; SAP enhancement package 2 for SAP NetWeaver 7.0 ; SAP enhancement package 3 for SAP NetWeaver 7.0

Keywords

Enterprise Portal, Knowledge Management, Mime Type, txt, html, content-type, text/plain, text/html, MIME Sniffing, Enterprise Portal 7.0, EP 7.0, Enterprise Portal 7.01, EP 7.01, Enterprise Portal 7.02, EP 7.02, Enterprise Portal 7.03, EP 7.03, Enterprise Portal 7.30, EP 7.30, Enterprise Portal 7.31, EP 7.31, Enterprise Portal 7.40, EP 7.4, Enterprise Portal 7.50, EP 7.5 , KBA , EP-KM-CM , KM Content Management , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP ONE Support launchpad (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.