[PyCS-devel] html_cleaner.py is not safe
Status: Alpha
Brought to you by:
myelin
|
From: Yasushi I. <ya...@lo...> - 2003-10-12 11:49:55
|
Hi, I found that html_cleaner.py allow user input of any html tag. For example, if you input < and > in comment form, PyCS converts to < and >. |