function readCookie(name) {
return (name = new RegExp('(?:^|;\\s*)' + ('' + name).replace(/[-[\]{}()*+?.,\\^$|#\s]/g, '\\$&') + '=([^;]*)').exec(document.cookie)) && name[1];
Hello to everyone, I'm security tester, I'm not used to test web security, so I'm here to ask you any help. Looking at the application page code, I've found that "exec" that it worries me. I tried to set up an interruption point with the Firefox debugger, but I can't do what I want/need. My question is: is it really possible to concatenate a command issuing a command execution exploit? Have I to report it as a possible flow, or there aren't any problems? Thank a lot
noyse