|
w3.org
»
w3.org - rdf
»
w3.org - www-rdf-validator
XSS vulnerability in RDF validation service
View:
Threaded
Chronologically
All Messages
New views
1 Messages —
Rating Filter:
0
1
2
3
4
5
Alert me
XSS vulnerability in RDF validation service
by Philip Taylor-5
:: Rate this Message:
Reply to Author
|
View Threaded
|
Show Only this Message
See
<
http://www.w3.org/RDF/Validator/ARPServlet?URI=http%3A%2F%2Fphilip.html5.org%2Fdemos%2Frdfa%2Fmisc02.html&PARSE=Parse+URI%3A+&TRIPLES_AND_GRAPH=PRINT_TRIPLES&FORMAT=PNG_EMBED
>
The validator displays strings without any escaping, allowing arbitrary
script code to be executed in the www.w3.org security context.
--
Philip Taylor
pjt47@...
Free embeddable forum
powered by
Nabble
Forum Help