Welcome Guest, Not a member yet? Register   Sign In
XML RPC > html in response > htmlspecialchars + javascript stripping
#4

[eluser]HdotNET[/eluser]
Wondering whether to post this as bug a or not.

The user guide implies that the XSS filter is not used by default, and must be turned on via the config file.

Yet the XML-RPC class is xss cleaning the data regardless of any setting in the config.

Anyone care to comment?


Messages In This Thread
XML RPC > html in response > htmlspecialchars + javascript stripping - by El Forum - 05-27-2008, 08:03 AM



Theme © iAndrew 2016 - Forum software by © MyBB