Bob,

Here is the URL that looks exactly like the URL of my application aside from
the context path:

http://click.avoka.com/click-examples/table/table-sorting.htm?actionLink=table-controlLink&column=</td>check&page=0

When I do the above with my application - I get an alert on some of the
pages.

When I actually use the above link - I don't get an alert, but I see a
message at the top of the page "Internet Explorer has modified this page to
help prevent cross-site scripting...."
My application also gives me this message sometimes instead of the alert,
not sure why some pages get an alert and some just this message, but I
believe the same thing is happening in all of these cases.
I believe the browser is actually encoding the script tags and that is why
this message comes up instead of the alert...
Thanks for looking at this!




--
View this message in context: 
http://click.1134972.n2.nabble.com/Javascript-is-executed-before-the-Filter-Cross-site-scripting-tp7392633p7398497.html
Sent from the click-user mailing list archive at Nabble.com.

Reply via email to