Together with the server-side stripslash() php function this call slips through the IE8 XSS filters because it strips the slashes server side and such evades IE8 detection when the HTTP request is being sent by IE8:
See: http://www.0x000000.com/?i=634
CISA Identifies Five New Vulnerabilities Currently Being Exploited
-
Of the five, one is a Windows vulnerability, another is a Cisco
vulnerability. We don’t have any details about who is exploiting them, or
how.
News arti...
6 hours ago
0 comments
Post a Comment