cure53 / jPurify

jPurify
Mozilla Public License 2.0
64 stars 11 forks source link

What are the current ways that javascript execution is possible with jQuery #7

Open DinisCruz opened 8 years ago

DinisCruz commented 8 years ago

I.e. the cases where jPurity is not able to help

cure53 commented 8 years ago

I think, the $.ajax/$.get/$.post API is worth mentioning here.

DinisCruz commented 8 years ago

yeah, and the idea is that we should have tests that prove it

cure53 commented 8 years ago

Soooo, do what now? :)

devd commented 8 years ago

I believe the latest version of jquery disabled the code exec via the Ajax methods by default.

On Jul 25, 2016 4:36 AM, "Cure53" notifications@github.com wrote:

Soooo, do what now? :)

— You are receiving this because you are subscribed to this thread. Reply to this email directly, view it on GitHub https://github.com/cure53/jPurify/issues/7#issuecomment-234929947, or mute the thread https://github.com/notifications/unsubscribe-auth/AAIXGSUhfT34vGd5scjHxdgADkb4w_l2ks5qZJ_QgaJpZM4JOBnz .