3 ms·
Odds are, it's to avoid Cross Site Scripting attacks. http://en.wikipedia.org/wiki/Cross-site_scripting http://en.wikipedia.org/wiki/Cross-site_scripting https
by YoAdrian 13y ago
Odds are, it's to avoid Cross Site Scripting attacks.
http://en.wikipedia.org/wiki/Cross-site_scripting http://en.wikipedia.org/wiki/Cross-site_scripting
https://www.owasp.org/index.php/Cross-site_Scripting_(XSS) https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)
- TazeTSchnitzel 13y agoThat makes no sense. It is trivial to use HTML entities (< and >) here. In fact, I think this is already done for comments. Test: <> Edit: <p>Test: <></font></span> Yep.