scaron / prettyphoto

prettyPhoto is a jQuery based lightbox clone. Not only does it support images, it also add support for videos, flash, YouTube, iFrames. It’s a full blown media lightbox. The setup is easy and quick, plus the script is compatible in every major browser.
http://www.no-margin-for-errors.com/projects/prettyPhoto-jquery-lightbox-clone/
553 stars 280 forks source link

fixed xss vulnerability #116

Closed Duncaen closed 9 years ago

Duncaen commented 11 years ago

Escape hashRel and parse hashIndex as integer. Example: http://www.no-margin-for-errors.com/projects/prettyPhoto-jquery-lightbox-clone/#prettyPhoto[pp_gal]/2,<a onclick="alert(1);">/