Re: Malicious-HTML vulnerabilities at deja.com

2000-03-20 Thread Dan Harkless
Geert Altena <[EMAIL PROTECTED]> writes: > > http://www.deja.com/getdoc.xp?AN=591804116 > > Comes out as (copy/paste from netscape): > > >> Forum: alt.test > >> Thread: >> src="http://www.in-design.com/~nsmart/foo.js"> >> onLoa

Re: Malicious-HTML vulnerabilities at deja.com

2000-03-20 Thread Geert Altena
You, Niall Smart, <[EMAIL PROTECTED]>, wrote: > deja.com does not always escape meta-characters when displaying ^^ > Usenet articles. Specifically, the article view page > (http://www.deja.com/getdoc.xp) and the thread view page > (http://www.deja.com/viewthread.xp) displ

Malicious-HTML vulnerabilities at deja.com

2000-03-16 Thread Niall Smart
Malicious-HTML vulnerabilities at deja.com Niall Smart, [EMAIL PROTECTED] 03/03/2000 Synopsis deja.com does not always escape meta-characters when displaying Usenet articles. Specifically, the article view page (http