Re: [Sks-devel] Fwd: CVE request: SKS non-persistent XSS

2014-05-02 Thread Kristian Fiskerstrand
Plerror is local logging and not passed to a web client On May 2, 2014 11:48 PM, Daniel Kahn Gillmor d...@fifthhorseman.net wrote: On 05/02/2014 07:35 AM, Kristian Fiskerstrand wrote: A non-persistent client-side cross-site scripting attack was reported against SKS[0] resulting from

Re: [Sks-devel] Fwd: CVE request: SKS non-persistent XSS

2014-05-02 Thread Daniel Kahn Gillmor
On 05/02/2014 06:24 PM, Kristian Fiskerstrand wrote: Plerror is local logging and not passed to a web client In that case, why use html_quote s for the arguments to plerror when handling Bad_request ? Thanks for such a quick response, --dkg signature.asc Description: OpenPGP digital