Antti-Juhani Kaijanaho: [SECURITY] Blosxom comments plugin cross-site scripting vulnerability [patch]

I only recently found out about the now weeks-old cross-site scripting vulnerability in Blosxom writeback plugin. Since the comments plugin, which I use, is based on the writeback plugin, it was logical to assume that it would also be vulnerable, and it is.

I adapted KyleM.xwell's patch for comments; here is the adapted patch. It works for me, but as always, there is no warranty, not even the implied warranty that the patch patches the vulnerability.

Update: Note that the patch only filters new comments; you need to manually check your existing comment base.

Re: [SECURITY] Blosxom comments plugin cross-site scripting vulnerability [patch]

But this patch would make non-western charactor mad....Like Chinese, maybe Japanese and Korean as well. Have any idea?

- ykhuang, to, 08 heinä  2004 09:26

Re: [SECURITY] Blosxom comments plugin cross-site scripting vulnerability [patch]

I don't immediately see how it would adversely affect Chinese and Japanese writing. Can you elaborate?

- Antti-Juhani Kaijanaho, to, 08 heinä  2004 14:11

