Comment 4 for bug 1902965

Revision history for this message
James Fournie (jfournie) wrote :

Here's some more fields I found that seem vulnerable:
010$a
245$abp

Also supercat HTML output is vulnerable (/opac/extras/supercat/retrieve/html/record/<id>)
260$c
260$b

Here's what I'm using to generate Evil MARC Records:
https://gist.github.com/jamesrf/1179f75ec51da878d0577a21575bffa5