PEAK XOOPS - Re: TinyEditor and My Album 2.84 in englishin japanese

Re: TinyEditor and My Album 2.84

List posts in the topic

none Re: TinyEditor and My Album 2.84

msg# 1.1.1.2.1.1
depth:
5
Previous post - Next post | Parent - Children.1 | Posted on 2007/2/15 3:10
GIJOE  ÀèǤ·³Áâ   Posts: 4110
Quote:

frankblack wrotes:
The big question is: if html is allowed, HOW it will be injected? Just by adding script-code into the wysiwyg-editor window?
You should learn POST data is independent from "form" (wysiwyg-editor window) completely.

Attackers can post malicious codes even via telnet.
Votes:9 Average:10.00

Posts tree

  Advanced search


Login
Username or e-mail:

Password:

Remember Me

Lost Password?

Register now!