Hacker News new | past | comments | ask | show | jobs | submit login

Aargh! The forum system actually sent a path of

">

to the server.




I don't think the commenting system is meant to process html. Perhaps it is a very loose regex of (http(s)?://.*)\s or whatever (sorry I didnt check to see thats valid!)

<a href='http://www.example.com/"'>¯\_(ツ)_/¯</a>




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: