Quantcast
Channel: Weblog | Sijmen Ruwhof » cross site scripting
Browsing latest articles
Browse All 4 View Live

Artikel gepubliceerd: Webprogrammer’s Hacking Guide

Op PHPFreakz.nl heb ik het artikel Webprogrammer’s Hacking Guide geplaatst. Dit artikel is bedoeld voor webprogrammeurs die veilig willen programmeren of bezorgd zijn over de veiligheid van hun...

View Article



PHP: htmlEntities() and Cross Site Scripting

When printing user input in an attribute of an HTML tag, the default configuration of htmlEntities() doesn’t protect you against Cross Site Scripting (XSS), when using single quotes to define the...

View Article

Image may be NSFW.
Clik here to view.

Cross-site scripting in millions of web sites

In August 2014 I found a severe cross-site scripting security vulnerability in the latest version (1.13.0) of the ‘jQuery Validation Plugin‘ during a security penetration test for a customer. This...

View Article

Image may be NSFW.
Clik here to view.

Mitigations against critical universal cross-site scripting vulnerability in...

This week David Leo disclosed a critical universal cross-site scripting vulnerability in fully patched Microsoft Internet Explorer 10 and 11 (from now on called the UXSS leak). He notified Microsoft on...

View Article
Browsing latest articles
Browse All 4 View Live




Latest Images