[Full-Disclosure] Safari/WebCore Content Sniffing

Jesse Ruderman jruderman at hmc.edu
Mon Aug 23 16:38:30 BST 2004


Mozilla does content sniffing on text/plain if the content includes 
control characters ("invalid text/plain content").  Is this incorrect?  
Is it a security hole -- for example, does it introduce XSS holes or 
allow executable files to be run without a proper warning?




Full-Disclosure is hosted and sponsored by Secunia.