Merge branch 'master' of ssh://git.ikiwiki.info/srv/git/ikiwiki.info
commit
116672d7d7
|
@ -466,7 +466,7 @@ with the comments plugin enabled. ([[!cve CVE-2011-0428]])
|
|||
|
||||
## possible javascript insertion via insufficient htmlscrubbing of alternate stylesheets
|
||||
|
||||
Tango noticed that 'meta stylesheet` directives allowed anyone
|
||||
Giuseppe Bilotta noticed that 'meta stylesheet` directives allowed anyone
|
||||
who could upload a malicious stylesheet to a site to add it to a
|
||||
page as an alternate stylesheet, or replacing the default stylesheet.
|
||||
|
||||
|
|
Loading…
Reference in New Issue