Cross-Site Scripting Cheat Sheet
Wow, this guy went to alot of work. He documented every (known) way a Cross-Site Scripting (XSS) can be launched. Update your regular expressions to clean all of these out! This can affect RSS aggregators as well.
Brad Neuberg's Weblog
Comments