Description

Style attribute can contain javascript, executed by IE.

Example

There are more example here: http://feedparser.org/docs/html-sanitization.html

Component selection

parser/html formatter.

Details

Server: MoinMoin 1.3 and later.

Browsers:

Workaround

Disable table style handling in the MoinMoin/formatter/text_html.py.

Discussion

Since only html in tables is the security issue: Disable the ability to use (besides the normal Moin syntax) also normal html markup in tabels. Why?

To conclude: In my eyes on the one hand you can do too much with html table markup (and mostly the wrong things) while on the other hand important things like the ability to mark tableheaders <th>, provide labels, a table summary etc (so that blind users can easily work with and navigate in tables) are missing completely. -- OliverSiemoneit 2007-04-15 16:33:38

Is that a IE bug or is that covered by html/css standards?

Plan


CategoryMoinMoinBug

MoinMoin: MoinMoinBugs/Sanitize style (last edited 2007-10-29 19:20:46 by localhost)