Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

test: use CSS hex-encoded strings to test sanitization #220

Merged
merged 1 commit into from Oct 29, 2021

Commits on Oct 29, 2021

  1. test: use CSS hex-encoded strings to test sanitization

    This adds onto #205. The original reported exploit in 2006 used CSS
    hex encoding (e.g., "\0075" for "u"), which was ...
    
    - mistakenly put into a double-quoted Ruby string in the Instiki test
      suite in 2007,
    - then copied into html5lib-ruby's test suite,
    - then copied into html5lib-python's suite,
    - then finally copied into the html5lib shared suite,
    - which was imported into Loofah
    flavorjones committed Oct 29, 2021
    Configuration menu
    Copy the full SHA
    587177d View commit details
    Browse the repository at this point in the history