summaryrefslogtreecommitdiff
path: root/handler.c
diff options
context:
space:
mode:
authorJo-Philipp Wich <jo@mein.io>2018-11-28 12:36:35 +0100
committerJo-Philipp Wich <jo@mein.io>2018-11-28 12:36:35 +0100
commitcdfc902a4cb77bc538a729f9e1c8a8578454a0e5 (patch)
tree22e20e398768b886c734e9891382b573367344c7 /handler.c
parent0bba1ce1129e79fa3907b16b31da44670fa19fc5 (diff)
cgi: escape url in 403 error output
Escape the untrusted request URL input in the permission denied HTML output. This fixes certain XSS vulnerabilities which can be leveraged to further exploit the system. Signed-off-by: Jo-Philipp Wich <jo@mein.io>
Diffstat (limited to 'handler.c')
0 files changed, 0 insertions, 0 deletions