]> Sergey Matveev's repositories - public-inbox.git/commitdiff
view: escape HTML description name
authorEric Wong <e@80x24.org>
Tue, 14 Mar 2017 21:23:39 +0000 (21:23 +0000)
committerEric Wong <e@80x24.org>
Tue, 14 Mar 2017 21:23:39 +0000 (21:23 +0000)
Otherwise funky filenames can cause HTML injection
vulnerabilities (hope you have JavaScript disabled!)


No differences found