> > Gerald, what about Embperl, does it escape \x8b? > No, there is no html escape for \x8b (and I guess the other one Matt mentioned is \0x8d for >) I know, so Embperl will not escape it, but this could be simply change by an entry in epchar.c. Any suggestion to what this should be escaped? Then I will make a patch. Gerald ------------------------------------------------------------- Gerald Richter ecos electronic communication services gmbh Internetconnect * Webserver/-design/-datenbanken * Consulting Post: Tulpenstrasse 5 D-55276 Dienheim b. Mainz E-Mail: [EMAIL PROTECTED] Voice: +49 6133 925151 WWW: http://www.ecos.de Fax: +49 6133 925152 -------------------------------------------------------------
- Re: Security in displaying arbitrary HTML Marc Slemko
- Re: Security in displaying arbitrary HTML Nick Tonkin
- Re: Security in displaying arbitrary HTML Marc Slemko
- Re: Security in displaying arbitrary HTML Steven Champeon
- Re: Security in displaying arbitrary HT... Vivek Khera
- Re: Security in displaying arbitra... Steven Champeon
- Re: Security in displaying arbitra... Marc Slemko
- Re: Security in displaying arbitra... Matt Sergeant
- Re: Security in displaying arb... Dirk Lutzebaeck
- Re: Security in displaying arb... Dirk Lutzebaeck
- RE: Security in displaying arb... Gerald Richter
- RE: Security in displaying arb... Matt Sergeant
- Re: Security in displaying arb... Marc Slemko
- Re: Security in displaying arb... Matt Sergeant
- Re: Security in displaying arb... Gunther Birznieks
- Re: Security in displaying arbitrary HTML John M Vinopal
- Re: Security in displaying arbitrary HTML Jeffrey W. Baker
- RE: Security in displaying arbitrary HTML Leon Brocard