Bug 550362

Summary: Use SafeERB
Product: [openSUSE] openSUSE 11.2 Reporter: Josef Reidinger <jreidinger>
Component: WebYaSTAssignee: Klaus Kämpf <kkaempf>
Status: RESOLVED WONTFIX QA Contact: E-mail List <qa-bugs>
Severity: Normal    
Priority: P5 - None CC: lslezak
Version: Factory   
Target Milestone: ---   
Hardware: Other   
OS: Other   
Whiteboard: security
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---
Bug Depends on:    
Bug Blocks: 514382    

Description Josef Reidinger 2009-10-27 11:36:22 UTC
Use SafeERB to sanitize (filter out html ) all inputs to prevent cross-site attack.
Comment 1 Ladislav Slezák 2009-10-27 16:15:10 UTC
BTW Edge Rails have enabled HTML escaping by default, see http://weblog.rubyonrails.org/2009/10/12/what-s-new-in-edge-rails