2 ms·
Check out http://code.google.com/p/owasp-esapi-js/source/browse/trunk/src/main/javascript/org/owasp/esapi/ http://code.google.com/p/owasp-esapi-js/source/browse
by marcinw 17y ago
Check out http://code.google.com/p/owasp-esapi-js/source/browse/trunk/src/main/javascript/org/owasp/esapi/ http://code.google.com/p/owasp-esapi-js/source/browse/trunk/...
While it may be overkill, replacing just < and > is nowhere near enough. You have to consider HTML attributes, URL's, CSS, and Javascript.
At an absolute minimum, these chars need to be encoded for the context they're rendered in:
< > ' " ( ) [ ] { }
and for good measure:
\ /
(disclaimer: any attacks that somehow bypass this (should not if done properly), would be truly unique to the application)