The program output returned by the backend is not escaped by the frontend. Instead the output is wrapped in <pre></pre> tags. This exposes the viewer of a submission to a possible HTML/JavaScript injection attack.

Submitted by Vlad Vergu on 24 February 2013 at 18:41

On 25 February 2013 at 09:06 Eelco Visser commented:

Fixed. Compiler output was using rawoutput instead of regular output.


On 25 February 2013 at 09:06 Eelco Visser closed this issue.

On 25 February 2013 at 09:06 Eelco Visser tagged 0.36

Log in to post comments