X-Git-Url: https://sipb.mit.edu/gitweb.cgi/ikiwiki.git/blobdiff_plain/370767bd1f057079881cf4fc38b98aa894b1f010..144540f546892d6fd949cdbb8fe990c6f4781085:/doc/security.mdwn diff --git a/doc/security.mdwn b/doc/security.mdwn index fb211cd12..916bd0484 100644 --- a/doc/security.mdwn +++ b/doc/security.mdwn @@ -466,7 +466,7 @@ with the comments plugin enabled. ([[!cve CVE-2011-0428]]) ## possible javascript insertion via insufficient htmlscrubbing of alternate stylesheets -Tango noticed that 'meta stylesheet` directives allowed anyone +Giuseppe Bilotta noticed that 'meta stylesheet` directives allowed anyone who could upload a malicious stylesheet to a site to add it to a page as an alternate stylesheet, or replacing the default stylesheet.