52c1f74ecc
Some more tests from Clint Ruoho. The main branch of Instiki (and, I guess, the old sanitizer) are vulnerable. Also: under Ruby 1.8.x, CGI.unescapeHTML screws up horribly decoding NCRs which represent high-bit ASCII characters. UTF-8 agrees with 7-bit ASCII, but CGI.unescapeHTML doesn't seem to know that they disagree for i>127. |
||
---|---|---|
.. | ||
chunks | ||
native/win32 | ||
caching_stuff.rb | ||
instiki_errors.rb | ||
node.rb | ||
page_renderer.rb | ||
rdocsupport.rb | ||
redcloth.rb | ||
sanitize.rb | ||
sanitizer.rb | ||
stringsupport.rb | ||
url_generator.rb | ||
wiki_content.rb | ||
wiki_words.rb |