Zabatak / Ushahidi_Web

Ushahidi is a platform that allows information collection, visualization and interactive mapping, allowing anyone to submit information through text messaging using a mobile phone, email or web form.
http://www.ushahidi.com
Other
1 stars 0 forks source link

Cross-Site Scripting Attack #11

Closed Safwat closed 12 years ago

Safwat commented 12 years ago

Description: When entering any malicious data in the report (like title is "?0we w!!)9e 023 23@#" ) the system not makes a validation error message, instead it accepts this input.

abbasadel commented 12 years ago

fixed