[<prev] [next>] [day] [month] [year] [list]
Message-Id: <200703122233.l2CMXnOx013308@faron.mitre.org>
Date: Mon, 12 Mar 2007 18:33:49 -0400 (EDT)
From: "Steven M. Christey" <coley@...re.org>
To: full-disclosure@...ts.grok.org.uk
Subject: Re: Is OWASP vulnerable ??
Not to reduce the high signal-to-noise ratio on this thread, but I
suspect there are lots of "eval injection" vulnerabilities in
Javascript-heavy applications, but they don't seem to be reported to
the usual places, or maybe people just call them XSS. Perl, PHP, and
other interpreted languages have eval injection too, but at least
they're reported occasionally.
- Steve
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists