mhonarc-dev

[approved] [bug #12930] Cross site scripting bug in m2h_text_html::filter

2005-05-02 11:09:15

Follow-up Comment #1, bug #12930 (project mhonarc):

mhtxthtml.pl has been updated in CVS to escape "vbscript" and
"ecmascript".

As for the other keywords, I'd like to have more information
on what browsers (or other software) support such scheme in
event handlers.


    _______________________________________________________

Reply to this item at:

  <http://savannah.nongnu.org/bugs/?func=detailitem&item_id=12930>

_______________________________________________
  Message sent via/by Savannah
  http://savannah.nongnu.org/

---------------------------------------------------------------------
To sign-off this list, send email to majordomo(_at_)mhonarc(_dot_)org with the
message text UNSUBSCRIBE MHONARC-DEV