Re: Security Markup

On 8/21/06, Kornel Lesinski <kornel@osiolki.net> wrote:
>
>
> > <div id="comment123"  nocode="true">
>
> I'm afraid that this would be too easy to bypass:
>
> <div id="comment123"  nocode="true">
>         $comment
> </div>
>
> $comment = '</div><script ...';

Not if you required the comments to be well-formed by themselves.

-- 

Orion Adrian

Received on Monday, 21 August 2006 12:55:45 UTC