March 2007 - Posts

Debug Message XSS Vulnerabilities
I was excited this afternoon when I thought that I'd stumbled upon a universal XSS vulnerability in verbose ColdFusion error messages. While testing a site, I had noted that a verbose debug error message (see below) echoed back many of the request Read More...
Posted 23 March 07 12:35 by Erik | 3 Comments   
Filed under ,