Yes, I mean that the label contents are set by some external entity -- a
user, a robot, a piece of malware, etc. :)

Dave


Matthew Gregory wrote:
> 
> Just a quick question, by user genererated do you mean the user enters 
> some text that is stored in a database and possibly shown to other users?
> 
> dmbaggett wrote:
>> Are there potential security issues with rich labels whose content is
>> user-generated? E.g., what if you set the text of a rich label to a
>> <script>
>> tag with code in it? In general, are rich labels vulnerable to cross-site
>> scripting attacks?
>> 
>> Dave
>> 
> 
> 
> ------------------------------------------------------------------------------
> Come build with us! The BlackBerry(R) Developer Conference in SF, CA
> is the only developer event you need to attend this year. Jumpstart your
> developing skills, take BlackBerry mobile applications to market and stay 
> ahead of the curve. Join us from November 9 - 12, 2009. Register now!
> http://p.sf.net/sfu/devconference
> _______________________________________________
> qooxdoo-devel mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/qooxdoo-devel
> 
> 

-- 
View this message in context: 
http://www.nabble.com/Security-implications-of-using-rich-labels-tp25777925p25787331.html
Sent from the qooxdoo-devel mailing list archive at Nabble.com.


------------------------------------------------------------------------------
Come build with us! The BlackBerry(R) Developer Conference in SF, CA
is the only developer event you need to attend this year. Jumpstart your
developing skills, take BlackBerry mobile applications to market and stay 
ahead of the curve. Join us from November 9 - 12, 2009. Register now!
http://p.sf.net/sfu/devconference
_______________________________________________
qooxdoo-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/qooxdoo-devel

Reply via email to