
• XSS
• Generally XSS is boring, but wait until we
talk about cookies….
• ColdFusion has scriptProtect helps strip out
<script> tags
• The blacklist used by scriptProtect:
<\s*(object|embed|script|applet|meta)
• Chris Eng’s Deconstruction CF whitepaper
goes into detail.
Attacking ColdFusion
Comentarios a estos manuales