[pmwiki-users] Form Input missing 4 types !!!!

Patrick R. Michaud pmichaud at pobox.com
Mon Aug 28 11:26:38 CDT 2006

On Mon, Aug 28, 2006 at 11:17:51AM -0500, JB wrote:
> > > No, because PmWiki doesn't provide any way for an author to
> > > add an "onClick" attribute to those button types.
> I think I just found a security risk.   I just tested this on 
> a just now newly installed, non-farm, non-customized pmwiki.
>     http://wiki.bybent.com/testwiki/pmwiki.php?n=Main.HomePage

I was kinda hoping you wouldn't find that.  :-)

But, now that it's out, I guess I'll have to close it.


More information about the pmwiki-users mailing list