Closed GoogleCodeExporter closed 9 years ago
Note that the stuff returned by toString isn't sanitized! I can put arbitrary
code/flash/whatever in there. It's direct access to setInnerHTML.
Original comment by metaw...@gmail.com
on 18 Jan 2008 at 1:38
And what container are you using? What's providing the implementation of the
innerHTML setter?
Original comment by mikesamuel@gmail.com
on 18 Jan 2008 at 5:04
The shindig container.
Original comment by metaw...@gmail.com
on 18 Jan 2008 at 4:12
Original comment by erights
on 28 Jan 2008 at 8:03
Original issue reported on code.google.com by
metaw...@gmail.com
on 18 Jan 2008 at 1:29