Hacker News new | past | comments | ask | show | jobs | submit login

> The other fix is properly escaping things before sticking them in your markup.

Or simply not displaying user data using a markup language with built-in remote code execution.




Well, yes, there are various levels of "thinking outside the box" here that could be applied.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: