|
Aaron Mulder made changes - 16/Jan/06 01:48 AM
Paul McMahan made changes - 19/Jan/06 04:01 AM
Paul McMahan made changes - 19/Jan/06 04:01 AM
Please note that the patch for the admin portlets does not address any XSS vulnerabilities in the sample applications. Based on recent discussion on the dev list my understanding is that the tomcat dev team will address any vulnerabilities in the samples they provide.
Aaron Mulder made changes - 26/Jan/06 06:35 AM
David Blevins made changes - 04/Aug/06 10:28 PM
Alan Cabrera made changes - 07/Aug/06 03:04 PM
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
"If escapeXml is true, the following character conversions are applied:
Character Character Entity Code
< <
> >
& &
' '
'' "