Quote:
Originally Posted by filburt1
It looks effective at first glance, but it makes assumptions on HTML that could change at any time.
|
The HTML will be submitted by users, think of it as posts, but unsubmit it will check then if any elements of JS injections are found, and if so - it will stop and warn them about it, telling them to remove it.
So they have to bypass this security before they can proceed to save the data.
- Zero Tolerance