XSS through dynamic Colors

A nice observation by Nikhil Kothari.

Another hole in HTML – but of course boils down to : don’t let your users cross the thin line between the data and control channel – or put otherwise : validate that input!

 

This entry was posted in Uncategorized. Bookmark the permalink.

Leave a comment