Click here to Skip to main content
15,909,953 members

Bugs and Suggestions

   

General discussions, site bug reports and suggestions about the site.

For general questions check out the CodeProject FAQs. To report spam and abuse Head to the Spam and abuse watch. If you wish to report a bug privately, especially those related to security, please email webmaster@codeproject.com

 
GeneralRe: XSS in codeproject.... Pin
Richard MacCutchan30-Jun-11 1:34
mveRichard MacCutchan30-Jun-11 1:34 
GeneralRe: XSS in codeproject.... Pin
Nish Nishant30-Jun-11 1:36
sitebuilderNish Nishant30-Jun-11 1:36 
GeneralRe: XSS in codeproject.... Pin
Shargon_8530-Jun-11 1:44
Shargon_8530-Jun-11 1:44 
GeneralRe: XSS in codeproject.... Pin
Richard MacCutchan30-Jun-11 2:00
mveRichard MacCutchan30-Jun-11 2:00 
GeneralRe: XSS in codeproject.... Pin
Nish Nishant30-Jun-11 2:10
sitebuilderNish Nishant30-Jun-11 2:10 
GeneralRe: XSS in codeproject.... Pin
Nish Nishant30-Jun-11 2:14
sitebuilderNish Nishant30-Jun-11 2:14 
GeneralRe: XSS in codeproject.... Pin
Richard MacCutchan30-Jun-11 3:49
mveRichard MacCutchan30-Jun-11 3:49 
GeneralRe: XSS in codeproject.... Pin
Nish Nishant30-Jun-11 4:10
sitebuilderNish Nishant30-Jun-11 4:10 
Richard MacCutchan wrote:
1. the user put input in description : the problem description contains the word
'input' ?

The article description contains the text "input". Maybe it's because you are not a regular author, but as someone who has written quite a few articles here, I am quite conscious of how an article has a title and a description. And considering his thread subject mentions XSS, I automatically assumed (rightly so) that input referred to the html tag.

Richard MacCutchan wrote:
2. and appears... : and appears what ?

He means that the INPUT control renders (or appears on screen). Again from (1) I already know he's talking about the INPUT-tag so I know that when he says appears, he means the control appears within the description.

Richard MacCutchan wrote:
3. one input... : ??

One INPUT-control appears (is rendered). he's re-stressing on how the control is showing up (when it shouldn't).

Richard MacCutchan wrote:
4. is a XSS ... : ?? or is this part of 3, in either case I don't see what it is
supposed to mean

What he means is that this is XSS in action here. No actual script in the example but it's trivial to add inline script to one of the control's events.

Richard MacCutchan wrote:
5. fix please : that I do understand

Wow, ok, I am surprised! Roll eyes | :rolleyes:

Once again I am not saying you or Nagy were being naive here, just that I was surprised at how something that was so obvious to me was so cryptic to you guys (and I know both of you are smart people).

Maybe I am just that good. Poke tongue | ;-P
Regards,
Nish
Are you addicted to CP? If so, check this out:
The Code Project Forum Analyzer : Find out how much of a life you don't have!

My technology blog: voidnish.wordpress.com

GeneralRe: XSS in codeproject.... Pin
Richard MacCutchan30-Jun-11 5:51
mveRichard MacCutchan30-Jun-11 5:51 
GeneralRe: XSS in codeproject.... Pin
Shargon_8530-Jun-11 1:46
Shargon_8530-Jun-11 1:46 
GeneralRe: XSS in codeproject.... Pin
Shargon_8530-Jun-11 1:50
Shargon_8530-Jun-11 1:50 
GeneralRe: XSS in codeproject.... Pin
Nish Nishant30-Jun-11 1:51
sitebuilderNish Nishant30-Jun-11 1:51 
GeneralRe: XSS in codeproject.... Pin
Chris Maunder30-Jun-11 1:49
cofounderChris Maunder30-Jun-11 1:49 
GeneralRe: XSS in codeproject.... Pin
Shargon_8530-Jun-11 1:53
Shargon_8530-Jun-11 1:53 
SuggestionBadly dated page Pin
Dan Neely29-Jun-11 10:37
Dan Neely29-Jun-11 10:37 
QuestionMissing Vote Pin
Jani Giannoudis29-Jun-11 6:03
mvaJani Giannoudis29-Jun-11 6:03 
AnswerRe: Missing Vote Pin
Dalek Dave29-Jun-11 6:18
professionalDalek Dave29-Jun-11 6:18 
AnswerRe: Missing Vote Pin
Chris Maunder29-Jun-11 7:55
cofounderChris Maunder29-Jun-11 7:55 
GeneralRe: Missing Vote Pin
Dalek Dave29-Jun-11 8:07
professionalDalek Dave29-Jun-11 8:07 
GeneralRe: Missing Vote Pin
Chris Maunder29-Jun-11 8:10
cofounderChris Maunder29-Jun-11 8:10 
GeneralRe: Missing Vote Pin
Dalek Dave29-Jun-11 10:10
professionalDalek Dave29-Jun-11 10:10 
SuggestionFree tools forum Pin
OriginalGriff29-Jun-11 3:01
mveOriginalGriff29-Jun-11 3:01 
GeneralRe: Free tools forum Pin
Hans Dietrich29-Jun-11 3:42
mentorHans Dietrich29-Jun-11 3:42 
GeneralRe: Free tools forum Pin
OriginalGriff29-Jun-11 3:53
mveOriginalGriff29-Jun-11 3:53 
GeneralRe: Free tools forum Pin
Hans Dietrich29-Jun-11 4:11
mentorHans Dietrich29-Jun-11 4:11 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.