Saturday, April 19, 2008, 12:03:05 AM, Randy Brown wrote:

> The form came up with nothing in the section. That's not surprising -
> I hadn't changed anything yet. What was surprising is that when I  
> exited the form I got this message instead of a page:

> FATAL::XSS hack attempt detected. Your IP has been logged.

> Have I been put on the international terrorist watchlist or  
> something?  What's going on?

Not quite, but watch out :))

I just added  a new measure which should prevent attacks aimed at
posting a script as an input key name.
Could you sent me your form, so I can see if there is anything
offensive? Are you using UTF charecters in field names? Or anything
containing a % ?


  ~Hans


_______________________________________________
pmwiki-users mailing list
[email protected]
http://www.pmichaud.com/mailman/listinfo/pmwiki-users

Reply via email to