PEAR is archived and read-only

This mirror preserves historical PEAR package releases and metadata so existing references remain available.

Home » HTML » HTML_Safe » Bug #9733

Security hole

Details

Request #9733Security hole
Submitted2007-01-04 12:48 UTC
Fromokin7 at yahoo dot fr
Assigneddemrit
StatusSuspended
PackageHTML_Safe
PHP VersionIrrelevant
Roadmaps(Not assigned)

Comments

[2007-01-04 12:48 UTC] okin7 at yahoo dot fr

Description:
------------
A new XSS security attack is being reported these days on the net, which affects the Adobe Acrobat Reader plugin.

See :
http://www.webappsec.org/lists/websecurity/archive/2007-01/msg00005.html
or
http://michaeldaw.org/md-hacks/backdooring-pdf-files/

It could a good idea to parse URLs in order to remove those dangerous strings ?