RE: Cross Site Scripting (XSS) issues with Struts 1.1-b2?

2002-09-09 Thread Van Riper, Mike
Some additional information, from reviewing the Struts 1.1-b2 source code, is interspersed below. -Original Message- From: Van Riper, Mike Sent: Sunday, September 08, 2002 9:29 PM To: List Struts-User (E-mail) Subject: Cross Site Scripting (XSS) issues with Struts 1.1-b2

Re: Cross Site Scripting (XSS) issues with Struts 1.1-b2?

2002-09-09 Thread Michael Rimov
At 09:29 PM 9/8/2002 -0700, you wrote: If you are not familiar with what I mean by cross site scripting (XSS), here are two links with information about it: http://www.cgisecurity.com/articles/xss-faq.shtml http://www.cert.org/advisories/CA-2000-02.html According to the first FAQ

Cross Site Scripting (XSS) issues with Struts 1.1-b2?

2002-09-08 Thread Van Riper, Mike
If you are not familiar with what I mean by cross site scripting (XSS), here are two links with information about it: http://www.cgisecurity.com/articles/xss-faq.shtml http://www.cert.org/advisories/CA-2000-02.html According to the first FAQ above, some of the things that should be done