Travis;
This just tripped a SECURITY ALERT in my app during a movie scrape!
Record: 313022 Trailer Path: Path: http://www.youtube.com/watch?v=
Html code in a database record??? Not good.
Please comment.
Joe
찾으시는 영화나 TV 프로그램이 없나요? 로그인 하셔서 직접 만들어주세요.
이 항목을 평가하거나 목록에 추가할까요?
회원이 아닌가요?
Joe Rose님의 댓글
6월 8, 2015 at 9:32 오후
Travis;
Sure enough! It executed in this post!
Travis Bell님의 댓글
6월 8, 2015 at 11:29 오후
Hi Joe,
I don't believe there's any sanitization on the video field. I've created a new ticket for this here. It's very much related to ticket #887, so I'll do them both at the same time.
LordMike님의 댓글
6월 15, 2015 at 5:04 오후
Uh .. just for the record. It is perfectly fine to have HTML or any other form of "code" or "markup" in the database. In fact - it should stay in that format.
It is YOUR job as a consumer to sanitize/encode values when presenting them, because only YOU know which format they should go in. (As an example, for HTML, there are different encodings depending on if you want some text in the body, attributes, javascript or css).
Mike