Opened 21 years ago
Closed 20 years ago
#1251 closed defect (bug) (fixed)
XSS and HTML injection
| Reported by: | anonymousbugger | Owned by: | matt |
|---|---|---|---|
| Priority: | normal | Milestone: | 2.1 |
| Component: | Security | Version: | 2.0.1 |
| Severity: | major | Keywords: | 2nd-opinion dev-feedback |
| Cc: | Focuses: |
Description
Change History (9)
#4
@
21 years ago
Mailing list threads discussing this:
http://comox.textdrive.com/pipermail/wp-hackers/2005-April/000530.html
http://comox.textdrive.com/pipermail/wp-hackers/2005-April/000517.html
Forum post:
#6
@
21 years ago
- Keywords bg|2nd-opinion bg|dev-feedback added
- Version → 2.0.1
Are we going to address this? Maybe we should be filtering the title through KSES except for people with unfiltered_html capability.
#7
@
20 years ago
Is kses really the best solution? I've been using SafeHTML with WorpPress since my first wp 2.0 installation. I suggest SafeHTML be given consideration as a replacement for kses - http://pixel-apes.com/safehtml/
Note:
See TracTickets
for help on using tickets.
![(please configure the [header_logo] section in trac.ini)](/chrome/site/your_project_logo.png)
If it's no issue then please take care of http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1102 and http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=304468