Enter Keywords:
1 - 10 of 14(0.019 seconds)
Sort By:
 
I am running an environment which uses ColdFusion 5.0 as the application server. I was trying to replicate, in a test environment, what is described as the "The Deadly Database Exploit". My SQL ...
Zones: Cold...Date Answered: 03/21/2002 Rating: 7.2 Views: 0
Functions.php is just for check the fields. What I need is a script that will help me to solve my CSS vulnerability. I am not sure if I have to use htmlentities or htmlspecialchars This form ...
Zones: PHPDate Answered: 09/29/2008 Rating: 9.2 Views: 0
What is best way to prevent cross site scripting? If user enters encoded value like for %3c for <, how to track this? plz provide examples.
Zones: JavaDate Answered: 01/15/2009 Rating: 6.8 Views: 0
Question:  Is the massive Twitter cross-site scripting error reported by Dave Naylor a valid issue?  Dave has a video showing the vulnerability, along with two blog articles explaining the problem....
Zones: Latest ThreatsDate Answered: 08/31/2009 Rating: 6.4 Views: 0
My ISP is telling me that my site is generating too many errors. I know they are because of the HackerSafe testing. I think I've fixed my "SQL Injection" vulnerabilities, so now it's on to cross si...
Zones: ColdFusion Studio, Network Vulnera...Date Answered: 05/12/2007 Rating: 8.6 Views: 0
_LASTFOCUS, a default parameter in ASP.NET 2.0, is vulnerable to reflexif cross site scripting (CSS). One suggested solution was to apply the patch MS06-056/KB922770 on the server. (Downloadabl...
Zones: ASP.Net Programming, Se...Date Answered: 09/01/2009 Rating: 7.2 Views: 0
I'm trying to decide how far I should let WYSIWIG capabilities go on my site. From any tests I've seen, done, or read about, Html Purifier, which I'm using, is as bullet proof as it says. I thought...
Zones: Web Development, HTML, Se...Date Answered: 11/04/2009 Rating: 7.8 Views: 4
I need to adhere to some bullshit PCI compliance.    the app is written in Coldfusion.   from what I've found on the web I gotta somehow check an url parm to make sure it doesn't have any html in i...
Zones: Network Vulnerabilities, Web Developme...Date Answered: 02/25/2009 Rating: 9.2 Views: 0
hi all the testing people has scanned the application i.e.,,(machine test) and found  that The test successfully embedded a script in the response, and it will be executed once the page is loaded...
Zones: Cold...Date Answered: 03/03/2009 Rating: 9.7 Views: 19
I have started using Server.HtmlEncode to add some kind of security to my little apps.  They work fine with it, but I want to verify it's actually encoding so I can show the boss.  Is there a way t...
Zones: C#, ASP.Net Programming, Programming Security Is...Date Answered: 04/28/2009 Rating: 9.1 Views: 4