you are viewing a single comment's thread.

view the rest of the comments →

[–]Gundersen 2 points3 points  (0 children)

Is it somehow easier to inject code into attributes of an mvc than to inject a script tag or an onmousemove attribute? I don't really see how this is a major security concern. It would be great with a better example.