##// END OF EJS Templates
Fix XSS reported on Security list...
Fix XSS reported on Security list No CVE-ID yet August 18, 2015 ----- Reported to Quantopian by Juan Broullón <thebrowfc@gmail.com>... If you create a new folder in the iPython file browser and set Javascript code as its name the code injected will be executed. So, if I create a folder called "><img src=x onerror=alert(document.cookie)> and then I access to it, the cookies will be prompted. The XSS code is also executed if you access a link pointing directly at the folder. jik ------
Matthias Bussonnier -
r21633:3ab41641
Show More
Name Size Modified Last Commit Author
/ docs / source / parallel / figs
asian_call.pdf Loading ...
asian_call.png Loading ...
asian_put.pdf Loading ...
asian_put.png Loading ...
dagdeps.pdf Loading ...
dagdeps.png Loading ...
hpc_job_manager.pdf Loading ...
hpc_job_manager.png Loading ...
mec_simple.pdf Loading ...
mec_simple.png Loading ...
parallel_pi.pdf Loading ...
parallel_pi.png Loading ...
simpledag.pdf Loading ...
simpledag.png Loading ...
single_digits.pdf Loading ...
single_digits.png Loading ...
two_digit_counts.pdf Loading ...
two_digit_counts.png Loading ...
wideView.png Loading ...