#5880: Cross-site(?) scripting when adding text via the "foreign key" popup 
window
-----------------------------------+----------------------------------------
   Reporter:  [EMAIL PROTECTED]  |                Owner:  nobody         
     Status:  new                  |            Component:  Admin interface
    Version:  SVN                  |           Resolution:                 
   Keywords:                       |                Stage:  Accepted       
  Has_patch:  1                    |           Needs_docs:  0              
Needs_tests:  0                    |   Needs_better_patch:  0              
-----------------------------------+----------------------------------------
Comment (by [EMAIL PROTECTED]):

 I think the "&" should be transformed _after_ all the others in the
 html_unescape function.

 """ should result in """, not "\"".

 Besides that, it's fine. Sorry that I posted it to the public trac. Could
 you perhaps add a sentence about security things to the "Read this first"
 section on the ticket page, so that this is more unlikely to happen again?

 Roland

-- 
Ticket URL: <http://code.djangoproject.com/ticket/5880#comment:4>
Django Code <http://code.djangoproject.com/>
The web framework for perfectionists with deadlines
--~--~---------~--~----~------------~-------~--~----~
You received this message because you are subscribed to the Google Groups 
"Django updates" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to [EMAIL PROTECTED]
For more options, visit this group at 
http://groups.google.com/group/django-updates?hl=en
-~----------~----~----~----~------~----~------~--~---

Reply via email to