[cowiki-dev] Re: XSS Vulnerability.

"Daniel T. Gorski" <[email protected]> Thu, 7 Jul 2005 20:24:23 +0200
Newsgroups gmane.comp.php.cowiki.devel
Message-ID <20050707182423.GX13654@bantha>
On 07 Jul 12:22, David Coallier wrote:

> Since wikis are really important and widely spread in todays world, the 
> reputation of an application and it's security is something that matters 
> to many people. I notice that the search field is failing to process the 
> basic user input rules[1].
> 
> http://cowiki.org/?cmd=srchdoc&q="><script>window.location='http://phpsec.org'</script>&x=0&y=0

Thank you. I forwarded your message to the coWiki development team as I am
not the maintainer anymore.

regards dtg