Re: JSP:includes parameter passing vulnerability

2010-09-15 Thread Michael Coates
Thanks for your replay. Will do. Moving conversation to user list. Michael Coates OWASP On 9/15/10 11:59 AM, Tim Funk wrote: > There is no issue. If there is a typo in the developer code, there is > a typo in the code. And sometimes typos cause security issues. As a > general rule, any code whi

Re: JSP:includes parameter passing vulnerability

2010-09-15 Thread Tim Funk
There is no issue. If there is a typo in the developer code, there is a typo in the code. And sometimes typos cause security issues. As a general rule, any code which is user provided should validated and output escaped. This is a topic which should be discussed on the user list. -Tim On 9/1