Xymon Mailing List Archive search

Hobbit Security (Cross-Site Scripting)

list Stewart L
Fri, 19 Jun 2009 11:18:52 -0400
Message-Id: <user-970f275f28dd@xymon.invalid>

It's usually a bit more complicated that just quoting the user input.   I'm
actually scanning a fresh install with IBM Appscan Enterprise when you
mentioned it... :)


On Fri, Jun 19, 2009 at 11:09 AM, David Cecchino <
user-e888dd4ad5ce@xymon.invalid> wrote:
 HP Webinspect scans of xymon show it is vulnerable to XSS , is there  a
way of putting quotes around the url variables/strings?

-- 
Stewart
--
An infinite number of mathematicians walk into a bar. The first one orders a
beer. The second orders half a beer. The third, a quarter of a beer. The
bartender says "You're all idiots", and pours two beers.