[Owasp-antisamy] AntiSAMY Defect

Serge Droganov sergei at droganov.ru
Sat Sep 20 05:55:25 EDT 2008

Hello Shishir,
I have reproduced the bug. Not sure why it doesn't appear on the  
server, but locally I get "Java heap space" message too.
I cut the code to spot the problem: <script>\"</script> this one  
throws the same error.

Arshan it looks like the code passes through Neko and error appears  
during the validation. It appears only inside <script> tag.
For example if we use: <style>\"</style> error does not appear.

Thank you,

On Sep 20, 2008, at 1:31 PM, Shishir Kumar wrote:

> <script type=\"text/javascript\">document.write(\"Hello World!\");</  
> script >

More information about the Owasp-antisamy mailing list