Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

SafeHTML UTF-7 And CSS Comment Tag Cross Site Scripting Vulnerabilities

SafeHTML is prone to cross-site scripting vulnerabilities, specifically in dealing with UTF-7 encoding of characters and with CSS comment tags.

Failure to filter HTML content can result in the exploitation of various latent vulnerabilities in Web based applications. A successful attack may facilitate HTML injection or cross-site scripting type issues.







 

Privacy Statement
Copyright 2009, SecurityFocus