[Zope] CERT -- Malicious HTML Tags

Julian Melville jmelvill@scu.edu.au
Sun, 6 Feb 2000 15:59:13 +1100


> Squishdot says this at the bottom of it's post article page:
>
> Allowed HTML
> <B> <I> <P> <A> <LI> <OL> <UL> <EM> <BR> <TT> <HR> <STRONG> <BLOCKQUOTE>
> <DIV .*> <DIV> <P .*>

It says that, presumably because it looks exactly like the equivalent
Slashdot form, but it doesn't seem to do anything meaningful to filter tags.
I've successfully posted tables, etc. to a Squishdot 0.3.2 forum without
problems.

Julian.