Tuesday, October 30, 2012

setHTML example , unsafe ?


I'm reading about XSS attacks and GWT unsafe code.

I've got a method ( client side)

public void print(String message)

And this method is invoked by others methods (client side) on this way:

this.print("<br>This is an error</br>");
this.print("<br>This is another error</br>");

Where is the unsafe code ? How is it possible to inject malicious code ?

Thanks and regards

