Cross site scripting in Domino? -
i have domino site getting highs cross site scripting on app scan.
we don't have license run appscan. group needs (yeah big corporations :) ). have noticed ie browser complain url such:
http://myserver.com/cld/cldg.nsf/vwtoc?openview&start=28 (ie warn on crosssite scripting such url).
i noticed notes.net forum site not come such error in ie, when try inject script tags. guess must scrub url before page rendered? how being done in notes.net forum? done @ server level or database level?
i did found thread
how avoid xsp/domino cross-site scripting vulnerability?
where steve mentions blog , web rules blog mentions not needed in 8.5.4. , above. understanding right? if @ 8.5.4. there still need scrub url?
edit: @ 8.5.3. not 8.5.4. mistaken. our admin going try steves's suggestions
Comments
Post a Comment