Matt Sergeant writes:

 > Unfortunately there's also a browser bug to contend with. They treat \x8b
 > (I think that's the right code) as < and there's a similar code for
 > >. Since most web developers are just doing s/</&lt;/g; they are open to
 > attacks based on character sets like this. Sad, but true. Even our loved
 > CGI.pm was (is?) open to this bug - I think Lincoln has fixed the
 > HTMLEncode function now though.

Gerald, what about Embperl, does it escape \x8b?

Dirk

Reply via email to