GithubHelp home page GithubHelp logo

Comments (9)

juice500ml avatar juice500ml commented on June 15, 2024 1

from coding-night-live.

punkyoon avatar punkyoon commented on June 15, 2024 1

수정한게 맞다고 생각합니다!

from coding-night-live.

minhoryang avatar minhoryang commented on June 15, 2024 1

엌ㅋㅋㅋㅋㅋ이게뭐얔ㅋㅋㅋㅋㅋㅋ내눈!!!

from coding-night-live.

punkyoon avatar punkyoon commented on June 15, 2024

kakaotalk_20170417_232718481

kakaotalk_20170417_232344711

from coding-night-live.

juice500ml avatar juice500ml commented on June 15, 2024

고쳐야 되는 부분:
https://github.com/dduk-ddak/coding-night-live/blob/master/static/js/cnl_chats.js#L287-L315
obj.description이 pure text로 들어감.

힌트:
http://stackoverflow.com/questions/9735045/is-jquery-text-method-xss-safe

@taeseunglee 해보실?

from coding-night-live.

juice500ml avatar juice500ml commented on June 15, 2024

동일 취약점이 전체에 걸쳐있음 ㅠ

Poll 취약점
https://github.com/dduk-ddak/coding-night-live/blob/master/static/js/cnl_chats.js#L379

Notice 취약점
https://github.com/dduk-ddak/coding-night-live/blob/master/static/js/cnl_chats.js#L342

from coding-night-live.

taeseunglee avatar taeseunglee commented on June 15, 2024

그래!

from coding-night-live.

punkyoon avatar punkyoon commented on June 15, 2024

채팅창으로 들어오는 모든 값들에 대해서 처리를 해줘야하네요

from coding-night-live.

taeseunglee avatar taeseunglee commented on June 15, 2024

기존의 out part의 모습.
2017-04-25 3 51 33

현재의 수정한 out part의 모습.
2017-04-25 3 52 21

이 부분도 이렇게 바꾸면 되겠죠!?

@punkyoon @juice500ml @fuzzythecat @minhoryang 여러분들은 어떤 것이 좋다고(혹은 옳다?) 생각하시나요!?

from coding-night-live.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.