Hi there,

We're using the struts rest plugin for our ajax driven site.

It seems like the JsonLibHandler performs no javascript escaping - thus
exposing us to XSS.
Any thought on this, anyone?

Stefan

-- 
BEKK Open
http://open.bekk.no

Reply via email to