Re: [cowiki-dev] Re: XSS Vulnerability.
"Daniel T. Gorski" <[email protected]> Fri, 8 Jul 2005 04:08:32 +0200
| Newsgroups | gmane.comp.php.cowiki.devel |
|---|---|
| Message-ID | <20050708020832.GA13654@bantha> |
On 07 Jul 20:24, Daniel T. Gorski wrote: > On 07 Jul 12:22, David Coallier wrote: > > > Since wikis are really important and widely spread in todays world, the > > reputation of an application and it's security is something that matters > > to many people. I notice that the search field is failing to process the > > basic user input rules[1]. > > > > http://cowiki.org/?cmd=srchdoc&q="><script>window.location='http://phpsec.org'</script>&x=0&y=0 > > Thank you. I forwarded your message to the coWiki development team as I am > not the maintainer anymore. The problem has been hopefully solved. If you want to try it again, you may try it at <http://dev.cowiki.org/> which represents the latest CVS of coWiki. Thank you. regards dtg