Re: [cowiki-dev] Re: XSS Vulnerability.

"Daniel T. Gorski" <[email protected]> Fri, 8 Jul 2005 04:08:32 +0200
Newsgroups gmane.comp.php.cowiki.devel
Message-ID <20050708020832.GA13654@bantha>
On 07 Jul 20:24, Daniel T. Gorski wrote:

> On 07 Jul 12:22, David Coallier wrote:
> 
> > Since wikis are really important and widely spread in todays world, the 
> > reputation of an application and it's security is something that matters 
> > to many people. I notice that the search field is failing to process the 
> > basic user input rules[1].
> > 
> > http://cowiki.org/?cmd=srchdoc&q="><script>window.location='http://phpsec.org'</script>&x=0&y=0
> 
> Thank you. I forwarded your message to the coWiki development team as I am
> not the maintainer anymore.

The problem has been hopefully solved. If you want to try it again, you may
try it at <http://dev.cowiki.org/> which represents the latest CVS of
coWiki.

Thank you.

regards dtg