...
For example, an application's strategy for avoiding Cross Site Scripting (XSS) vulnerabilities may include forbidding <script>
tags in inputs. Such black-listing mechanisms are a useful part of a security strategy, even though they are insufficient for complete input validation and sanitization. When implemented, this form of validation must be performed only after normalizing the input.
Wiki Markup |
---|
Character information in Java 1.6 is based on the Unicode Standard, version 4.0 \[[Unicode 2003|AA. Bibliography#Unicode 2003]\]. Character information in Java 1.6 is based on the Unicode Standard, version 6.0.0 \[[Unicode 2011|AA. Bibliography#Unicode 2011]\]. |
Wiki Markup |
---|
According to the Unicode Standard \[[Davis 2008|AA. Bibliography#Davis 08]\], annex #15, Unicode Normalization Forms |
...
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="5f7ffa2bf66657f8-9abebb4f-47f04b7a-9d868608-7d6ba4077adede2f6870bb10"><ac:plain-text-body><![CDATA[ | [[MITRE 2009 | AA. Bibliography#MITRE 09]] | [CWE ID 289 | http://cwe.mitre.org/data/definitions/289.html] "Authentication Bypass by Alternate Name" ]]></ac:plain-text-body></ac:structured-macro> |
| CWE ID 180 "Incorrect Behavior Order: Validate Before Canonicalize" |
...
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="6d488b7607ca28c6-89ed75c5-451d486b-9aa3a391-eb56e5f90fc21ffc6b18087f"><ac:plain-text-body><![CDATA[ | [[API 2006 | AA. Bibliography#API 06]] | ]]></ac:plain-text-body></ac:structured-macro> |
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="ef51b9da09af8fb3-c0b55f59-4efc47f5-b3068ece-608f024a3daafdd53c23e2e6"><ac:plain-text-body><![CDATA[ | [[Davis 2008 | AA. Bibliography#Davis 08]] | ]]></ac:plain-text-body></ac:structured-macro> |
<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="8be8e7aaacf757ac-e2257b04-4a0047e7-aef3b549-fd97b233b70ce7b584f563d0"><ac:plain-text-body><![CDATA[ | [[Weber 2009 | AA. Bibliography#Weber 09]] | ]]></ac:plain-text-body></ac:structured-macro> |
...