[pLog-svn] xss in 1.2.7

Jon Daley plogworld at jon.limedaley.com
Mon May 5 16:03:10 EDT 2008


On Sat, 3 May 2008, Mark Wu wrote:
> But, the problem is he can do the same thing with template editor .... I
> have no idea how to prevent ...

 	And this is because this input can't have html filtered out, 
right?

 	What if we go back to the nonce/time-based keys that we talked 
about before?  That can filter out lots of bad requests, can't it?


More information about the pLog-svn mailing list