Home » HTML » HTML_Safe » Bug #9733
Security hole
Details
| Request #9733 | Security hole |
|---|---|
| Submitted | 2007-01-04 12:48 UTC |
| From | okin7 at yahoo dot fr |
| Assigned | demrit |
| Status | Suspended |
| Package | HTML_Safe |
| PHP Version | Irrelevant |
| Roadmaps | (Not assigned) |
Comments
[2007-01-04 12:48 UTC] okin7 at yahoo dot fr
Description:
------------
A new XSS security attack is being reported these days on the net, which affects the Adobe Acrobat Reader plugin.
See :
http://www.webappsec.org/lists/websecurity/archive/2007-01/msg00005.html
or
http://michaeldaw.org/md-hacks/backdooring-pdf-files/
It could a good idea to parse URLs in order to remove those dangerous strings ?