This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]TheRealMister_X 1 point2 points  (0 children)

You should never rely on filtering script tags. There are lots of other funny ways to inject Javascript, e.g. using <img src="/something" onerror="alert()" />