You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
There should be a filter that restricts the input method. For instance I am
getting a lot of reports of dom based xss via cookie value, and I don't care
because this isn't exploitable. Some people might care, so there should be a
configuration option. I have noticed that referer is also very common, and it
might be nice to filter for that as well.
Original issue reported on code.google.com by [email protected] on 3 Sep 2011 at 1:27
The text was updated successfully, but these errors were encountered:
Original issue reported on code.google.com by
[email protected]
on 3 Sep 2011 at 1:27The text was updated successfully, but these errors were encountered: