Follow us on Twitter
Latest Tweet: New blog post on raw roles allowing arbitrary html in docutils < 0.6 http://blog.projectfondue.com/2010/7/27/security-raw-roles-in-docutils
L'Alpiniste

The blog of the Project Fondue Team

Entries tagged “restructuredtext”

Security: Raw Roles in Docutils

written by Stuart Colville, on 27 July, 2010 at 21:48.

Whilst we were making our reStructuredText API site, we found a flaw in docutils 0.5 which made it possible to inject arbitrary html and javascript into any website or wiki which allows third parties to provide content via restructured text.

Read the full post on “Security: Raw Roles in Docutils”