#5880: Cross-site(?) scripting when adding text via the "foreign key" popup
window
--------------------------------+-------------------------------------------
Reporter: [EMAIL PROTECTED] | Owner: nobody
Status: new | Component: Admin interface
Version: SVN | Keywords:
Stage: Unreviewed | Has_patch: 0
--------------------------------+-------------------------------------------
When I entered the following text into a text field, a JavaScript message
box popped up:
</script><script>alert('foo');</script>
You need to encode the "</script>" to prevent this from happening.
--
Ticket URL: <http://code.djangoproject.com/ticket/5880>
Django Code <http://code.djangoproject.com/>
The web framework for perfectionists with deadlines
--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups
"Django updates" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to [EMAIL PROTECTED]
For more options, visit this group at
http://groups.google.com/group/django-updates?hl=en
-~----------~----~----~----~------~----~------~--~---