Re: CERT Advisory on malicious scripts

This WebDNA talk-list message is from

2000


It keeps the original formatting.
numero = 27025
interpreted = N
texte = Can someone tell me all the places I would need to convert the < char into nothing to prevent maliciousnous?1) Only when displaying as HTML on a page a malicious user could access? 2) What about inside textareas that user has access to? 3) How about on an admin only page? - Could the malicious doer input a