HomePhorge

Fix XSS hole in YouTube remarkup rule

Description

Fix XSS hole in YouTube remarkup rule

Summary:
The source wasn't properly escaped.

Test Plan:
Made a comment like "http://youtube.com/?v="></iframe><h1>!!!</h1>"

Reviewed By: mroch
Reviewers: tomo, mroch, tuomaspelkonen, aran, jungejason
CC: aran, mroch
Differential Revision: 516

Details

Provenance
epriestleyAuthored on Jun 24 2011, 10:43 AM
themackabuPushed on Mar 25 2025, 8:07 PM
Parents
rPfe04d8bf70e8: Remove UTF-8 kludges from Differential
Branches
Unknown
Tags
Unknown

Event Timeline