Re: Tips on server-side URL sanitizing?

2005-09-19 Thread Frank Hecker
Thanks for the info! Frank -- Frank Hecker [EMAIL PROTECTED] ___ Mozilla-security mailing list Mozilla-security@mozilla.org http://mail.mozilla.org/listinfo/mozilla-security

Re: Tips on server-side URL sanitizing?

2005-09-18 Thread Gervase Markham
Frank Hecker wrote: First, I won't be allowing HTML tags in submitted comments. My plan was to simply use the Perl CGI::EscapeHTML function (Blosxom is written in Perl) to convert '', '', double quote, and 0x8b and 0x9b to the corresponding HTML character entities prior to the submitted