projects
/
ikiwiki.git
/ commitdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
| commitdiff |
tree
raw
|
patch
| inline |
side by side
(parent:
370767b
)
use real name
author
Giuseppe Bilotta
<giuseppe.bilotta@gmail.com>
Mon, 28 Mar 2011 17:00:25 +0000
(19:00 +0200)
committer
Giuseppe Bilotta
<giuseppe.bilotta@gmail.com>
Mon, 28 Mar 2011 17:00:25 +0000
(19:00 +0200)
doc/security.mdwn
patch
|
blob
|
history
diff --git
a/doc/security.mdwn
b/doc/security.mdwn
index fb211cd12285fffc8652096d64859f956fc4d95e..916bd048440b252232fc4e8b3bd21ebad6d5c7ff 100644
(file)
--- a/
doc/security.mdwn
+++ b/
doc/security.mdwn
@@
-466,7
+466,7
@@
with the comments plugin enabled. ([[!cve CVE-2011-0428]])
## possible javascript insertion via insufficient htmlscrubbing of alternate stylesheets
-
Tango
noticed that 'meta stylesheet` directives allowed anyone
+
Giuseppe Bilotta
noticed that 'meta stylesheet` directives allowed anyone
who could upload a malicious stylesheet to a site to add it to a
page as an alternate stylesheet, or replacing the default stylesheet.