Comment 1 for bug 1183884

Revision history for this message
Samuel Merritt (torgomatic) wrote : Re: Unescaped content embedded in XML

I don't know about exploitability, but it's certainly true that an account named AUTH_" produces this little pile of invalid XML on GET:

<?xml version="1.0" encoding="UTF-8"?>
<account name="AUTH_"">
</account>