Re: XSS Vulnerability in Struts 2 before 2.2.3

2011-05-11 Thread Maurizio Cucchiara
2:37 PM > To: Struts Users Mailing List > Subject: Re: XSS Vulnerability in Struts 2 before 2.2.3 > > I did not checked before, but I bet it works (Please Let us know if it > doesn't). > > > On 11 May 2011 16:47, Sarr, Nathan wrote: >> Hello, >> &g

RE: XSS Vulnerability in Struts 2 before 2.2.3

2011-05-11 Thread Sarr, Nathan
I did a quick test and it appeared to work correctly. -Nate -Original Message- From: Maurizio Cucchiara [mailto:maurizio.cucchi...@gmail.com] Sent: Wednesday, May 11, 2011 12:37 PM To: Struts Users Mailing List Subject: Re: XSS Vulnerability in Struts 2 before 2.2.3 I did not checked

Re: XSS Vulnerability in Struts 2 before 2.2.3

2011-05-11 Thread Maurizio Cucchiara
I did not checked before, but I bet it works (Please Let us know if it doesn't). On 11 May 2011 16:47, Sarr, Nathan wrote: > Hello, > > > >   I noticed the solution mentions turning off DMI support in > struts.xml.  Would the same result be achieved by setting it in the > struts.properties file: