Merge branch 'master' of ssh://git.ikiwiki.info/srv/git/ikiwiki.info

master
Joey Hess 2011-03-28 13:09:14 -04:00
commit 116672d7d7
1 changed files with 1 additions and 1 deletions

View File

@ -466,7 +466,7 @@ with the comments plugin enabled. ([[!cve CVE-2011-0428]])
## possible javascript insertion via insufficient htmlscrubbing of alternate stylesheets
Tango noticed that 'meta stylesheet` directives allowed anyone
Giuseppe Bilotta noticed that 'meta stylesheet` directives allowed anyone
who could upload a malicious stylesheet to a site to add it to a
page as an alternate stylesheet, or replacing the default stylesheet.