]> git.ipfire.org Git - thirdparty/squid.git/commit - lib/html_quote.c
Everywhere where Squid inserts text received from the network into
authorwessels <>
Wed, 22 Nov 2000 04:14:44 +0000 (04:14 +0000)
committerwessels <>
Wed, 22 Nov 2000 04:14:44 +0000 (04:14 +0000)
commitd8f20e858f97f39da2e85deebffe442a18190ecf
treee6c70afd1c872faf8a6ab9bc97ef807fd03c290a
parent530c32335c2afb0567b3defd296caa9455f266b2
Everywhere where Squid inserts text received from the network into
a HTML page (error pages, FTP listings, Gopher listings, ...) care
must be taken to ensure that the text is properly encoded as HTML,
or a malicious user might be able to insert script code or other
HTML tags, and exploit the web browser of any user visiting their
page or clicking on that funny link received in a email..
lib/html_quote.c