Cross site scripting in Domino? -


i have domino site getting highs cross site scripting on app scan.

we don't have license run appscan. group needs (yeah big corporations :) ). have noticed ie browser complain url such:

http://myserver.com/cld/cldg.nsf/vwtoc?openview&start=28 (ie warn on crosssite scripting such url).

i noticed notes.net forum site not come such error in ie, when try inject script tags. guess must scrub url before page rendered? how being done in notes.net forum? done @ server level or database level?

i did found thread

how avoid xsp/domino cross-site scripting vulnerability?

where steve mentions blog , web rules blog mentions not needed in 8.5.4. , above. understanding right? if @ 8.5.4. there still need scrub url?

edit: @ 8.5.3. not 8.5.4. mistaken. our admin going try steves's suggestions


Comments

Popular posts from this blog

linux - Does gcc have any options to add version info in ELF binary file? -

android - send complex objects as post php java -

charts - What graph/dashboard product is facebook using in Dashboard: PUE & WUE -