Assuring Security by testing

Frédéric Buclin lpsolit at gmail.com
Sun May 4 18:42:09 UTC 2008


Gervase Markham a écrit :
> It would be interesting to go back through the XSS holes which have been 
> found since this system was created, and see why it didn't catch them.

Because some variables were added to filterexceptions.pl despite they 
were not safe (e.g. a variable assumed to be an integer but which is not 
always an integer).



More information about the developers mailing list