features vulnerability

Events happening in the community are now at Drupal community events on www.drupal.org.
ingo86's picture

Xss from URL...

Hi all,
The scanner is tested to find XSS vulnerabilities inside a drupal installation. These could be found only searching into the forms of the website. There's no way right now to add an exploit as a parameter of the url of the page.
Something like
http://www.example.com/?q=<script>alert(xss);</script>
This is something I wanna add as new feature, but make it automatic is not so trivial.
Suggestions?

Read more
Subscribe with RSS Syndicate content