Am 23.10.2013 18:44, schrieb Colin Watson: > For completeness, are we happy that JavaScript injection into server-side > application code (e.g. node.js) is best described as "command injection" > and not any sort of XSS? > > Colin +1 +1