I enjoyed the article, but I wish it would have addressed sites (like this one) that allow users to input markup.
Is parsing out script tag sections enough to close the hole, or are there other mechanisms that have to be addressed?
In reply to Re: Preventing Cross-site Scripting Attacks
by converter
in thread Preventing Cross-site Scripting Attacks
by grep
For: | Use: | ||
& | & | ||
< | < | ||
> | > | ||
[ | [ | ||
] | ] |