|
Please note that the patch for the admin portlets does not address any XSS vulnerabilities in the sample applications. Based on recent discussion on the dev list my understanding is that the tomcat dev team will address any vulnerabilities in the samples they provide.
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
"If escapeXml is true, the following character conversions are applied:
Character Character Entity Code
< <
> >
& &
' '
'' "