Hi.
If you do allow them to use their own CSS, be careful not to let them use url() values, as that could make your users vulnerable to XSS attacks.
(As well as any other style that would allow loading of external resources... can't think of any more of them at the moment)
Yes, there are a number of them. There have been a a lot of reports of worms in sites that allow CSS from users (myspace worm). I'm sure it will be hard if not impossible to clean your CSS.
http://www.thespanner.co.uk/category/css/
Funny thing is you can't really search for "css xss" since CSS is another acronym for XSS.
Last edited by digital-ether; Jun 12th, 2009 at 7:00 pm.
Reputation Points: 457
Solved Threads: 101
Nearly a Posting Virtuoso
Offline 1,250 posts
since Sep 2005