Description

Some input string are not quoted properly. This can be used for cross site scripting (XSS).

Ask FlorianFesti for details.

Additionally, some parsers might reveal user's original input.

Ask AlexanderSchremmer for details.

Details

MoinMoin Version

1.1 - 1.3

Workaround

Plan


CategoryMoinMoinBugFixed

MoinMoin: MoinMoinBugs/QuotingMissing (last edited 2007-10-29 19:20:31 by localhost)