I think this is called "cross site scripting attack" and should be
prevented...
"output field" is simply a read-only widget with a value, and browsers
should not interpret any pure HTML values of such objects...

Marcel Rouwenhorst wrote:
> 
> Is it possible to display formatted html in a cforms output field?
> 

-- 
View this message in context: 
http://www.nabble.com/displaying-html-in-a-cforms-field-tf985897.html#a7343464
Sent from the Cocoon - Users mailing list archive at Nabble.com.


---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to