Link: Spring-MVC Cross-Site Scripting Vulnerabilities
Sverre Huseby examines some security issues with Spring-MVC. As it turns out, the Spring JSP form-taglib provide no HTML-escaping by default, making it very easy to get Cross-Site Scripting vulnerabilities included in the code. The article comes complete with a standalone application that illustrates the problem.
This work is licensed under a
Creative Commons Attribution 3.0 License.
Print This Post