Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Web Application Security
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
Re: XSS - Double Quote break out and White Space filtered May 30 2009 05:17AM
arvind doraiswamy (arvind doraiswamy gmail com)
Thanks Jeff and Florian.
@Jeff: All the other whitespace characters were blocked off as well.
The backticks one worked on this one though so Problem1 is solved.
@Florian: = was allowed and we managed to do this with an onChange
event handler. There might be a better event handler too though,
didn't ...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus