QuackFuzed.com is the personal ColdFusion coding blog of Matt Quackenbush. It exists primarily as a place for the author to learn, and hopefully to assist others in learning and/or avoiding some of the same pitfalls and mistakes. (Quack certainly makes enough mistakes daily to make up for the entire ColdFusion community.)
cfUniForm v4.6.0 - IMPORTANT PrettyComments XSS Vulnerability Fix Release
Posted on September 11, 2011 at 5:38 PM in ColdFusion, Uni-Form Tag Library, jQuery
IMPORTANT: If you have textareas in any of your forms, you will want to upgrade!
A big THANK YOU! to Marc Esher for identifying an XSS vulnerability with the plugin that cfUniForm had previously used for "expandable" textareas. Marc contacted the author of the PrettyComments jQuery plugin repeatedly in an effort to help the author resolve this issue. However, the author gave no indication that he was interested in a fix. Because of this, cfUniForm now uses Elastic for expandable textareas.
Latest Articles
- No recent entries.
Categories
- ColdBox (21) [RSS]
- ColdFusion (92) [RSS]
- Fusebox (3) [RSS]
- General (22) [RSS]
- jQuery (15) [RSS]
- Kalendar (1) [RSS]
- Linux (1) [RSS]
- Mura CMS (1) [RSS]
- Railo (1) [RSS]
- Rants (5) [RSS]
- Transfer (8) [RSS]
- Uni-Form Tag Library (36) [RSS]
Quick Links
Blogs I Read
Calendar
| S | M | T | W | T | F | S |
|---|---|---|---|---|---|---|
| « Aug | Oct » | |||||
| 1 | 2 | 3 | ||||
| 4 | 5 | 6 | 7 | 8 | 9 | 10 |
| 11 | 12 | 13 | 14 | 15 | 16 | 17 |
| 18 | 19 | 20 | 21 | 22 | 23 | 24 |
| 25 | 26 | 27 | 28 | 29 | 30 | |
Subscribe
Enter a valid email address.



On 9/12/11 at 10:36 PM, Glenn said:
On 9/13/11 at 12:07 AM, Matt Quackenbush said:
On 12/30/11 at 6:54 AM, Matthew said:
On 2/9/12 at 6:07 AM, Matt Quackenbush said:
http://www.quackfuzed.com/demos/cfUniForm/
:-)
On 4/13/12 at 2:38 AM, George Murphy said:
On 6/13/12 at 9:43 PM, Matt Quackenbush said: