Posted by Ben Holness on 05/05/06 02:22
Hi,
I am thinking about opening a web site which will allow people to register
and then have direct access to a stylesheet in order to brand their page.
When a user saves their stylesheet, the system will reject it if it
includes any of the '<', '>' or '?' characters. I know this restricts some
CSS, but that's fine for my purposes.
Is there anything else I should check for? How vulnerable does having this
option leave me?
Cheers,
Ben
[Back to original message]
|