Quantcast
Channel: InformAction Forums
Viewing all articles
Browse latest Browse all 17374

Re: XSS exclusion for msdn.microsoft.com to plusone.google.c

$
0
0
That's a nasty query string you have there :D

If you're confident that Google +1 is not actually vulnerable to an XSS attack, then you could try something like:
^https://plusone\.google\.com/.*

I'm not sure of the details of the XSS filter, but it's possible that Giorgio will find a way to improve it so that the exception is not needed.

Viewing all articles
Browse latest Browse all 17374

Trending Articles