On Sun, 2012-12-30 at 15:55 +0000, Jonathan Wiltshire wrote: > Please unblock mediawiki-extensions to fix the security bug #696179 (no CVE > has been assigned yet). This resolves an XSS attack on any user of a wiki > importing a malicious RSS feed (insufficient escaping). Any idea what the comment in ++ array('a', /* does not work */ 'img'))); is about? Regards, Adam