- From: vyv03354 <notifications@github.com>
- Date: Sat, 12 Dec 2015 17:46:13 -0800
- To: whatwg/encoding <encoding@noreply.github.com>
Received on Sunday, 13 December 2015 01:46:41 UTC
> Only WebKit based browsers seem not to output ESC, SI and SO to the encoded bytes. But removing characters may be another XSS vector (e.g. "<[0x0E]script"). --- Reply to this email directly or view it on GitHub: https://github.com/whatwg/encoding/issues/15#issuecomment-164209669
Received on Sunday, 13 December 2015 01:46:41 UTC