Re: [BUG] gitweb: XSS vulnerability of RSS feed
- From
Kevin <ikke@ikke.info>
- Date
- Nov 13, 2012, 15:45 UTC
- Message-ID
- <CAO54GHCzeWv41Bu5By0JOzbBHGuzXV=krdDr0U=QsMBun7PF7A@mail.gmail.com>
- In-Reply-To
- <CAM9Z-nkuHj8MWLfWsvY=EqHXCUS+Pk5Ezv6m5J+cnh7cQHNc_g@mail.gmail.com>
The problem with input filtering is that you can only filter for one output scenario. What if the the input is going to be output in a wiki like environment, or to pdf, or whatever? Then you have to unescape the data again, and maybe apply filtering/escaping for those environments.
You only know how to escape data when you are going to output it, so then is the the best moment to escape it.