Talk:JSP JSTL

From OWASP
Revision as of 15:09, 11 March 2008 by Tehmina (Talk | contribs)

(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to: navigation, search

A few things need clarification:

  • cookie - anything juicy? I can't remember what my problem was with this implicit object.
  • <c:redirect> - splitting?
  • <sql:query>, <sql:update> - injection? I couldn't get this to work.
  • <sql:param> - if sql injection is possible then this would essentially work like prepared stmts right?