Re: Suggestion on how to eliminate Cross-site-scripting (XSS) bugs for good.
Alex Kapranoff <[email protected]>
| Newsgroups | gmane.comp.lang.perl.modules.html-template |
|---|---|
| Organization | Inner Mongolia |
| Message-ID | <[email protected]> |
* Shlomi Fish <[email protected]> [October 17 2006, 14:23]: > Now what I want is to sub-class HTML::Template so we'll always have to > use "ESCAPE=HTML". If we want to override it we'll need to do the following: There's `default_escape' option in recent HTML::Template. Is it not enough? -- Alex Kapranoff, $n=["1another7Perl213Just3hacker49"=~/\d|\D*/g]; $$n[0]={grep/\d/,@$n};print"@$n{1..4}\n" ------------------------------------------------------------------------- Using Tomcat but need to do more? Need to support web services, security? Get stuff done quickly with pre-integrated technology to make your job easier Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642