Homec4science

Fix XSS hole in YouTube remarkup rule

Authored by epriestley <git@epriestley.com> on Jun 24 2011, 19:43.

Description

Fix XSS hole in YouTube remarkup rule

Summary:
The source wasn't properly escaped.

Test Plan:
Made a comment like "http://youtube.com/?v="></iframe><h1>!!!</h1>"

Reviewed By: mroch
Reviewers: tomo, mroch, tuomaspelkonen, aran, jungejason
CC: aran, mroch
Differential Revision: 516

Details

Committed
epriestley <git@epriestley.com>Jun 24 2011, 19:45
Pushed
aubortJan 31 2017, 17:16
Parents
rPHfe04d8bf70e8: Remove UTF-8 kludges from Differential
Branches
Unknown
Tags
Unknown

Event Timeline

epriestley <git@epriestley.com> committed rPH4bfbd209b224: Fix XSS hole in YouTube remarkup rule (authored by epriestley <git@epriestley.com>).Jun 24 2011, 19:45