Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: MagpieRSS XSS 0day Dec 29 2008 10:24PM
Antone Roundy (electriceel gmail com)
admin (at) elites0ft (dot) com [email concealed] wrote:
> it is a simple fix: htmlentities() around the parsed CDATA.

The problem with this solution is that if the feed contains harmless
HTML that's used for formatting, the HTML code becomes visible and the
formatting is lost.

A better solution is to strip out HTML tags. E...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus