Skip to content

Resources: Unchkecked injection of query string #384

Closed
@gabrielschulhof

Description

@gabrielschulhof

Accessing http://api.jquerymobile.com/resources/results.php?choice=%3Cimg%20src=http://i.imgur.com/W57wiZ0.jpg%3E results in the value of the query variable choice becoming a markup snippet within the page.

Metadata

Metadata

Labels

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions