Menu

#36 Templates don't use |escape:'html'

open
nobody
None
5
2010-10-10
2010-10-10
Lazy
No

After fixing SQL injections in recordwrite.php I noticed that you get pretty interesting results if yuo create a TXT record like this:
"><script> alert("test"); </script>"

Discussion


Log in to post a comment.