Ray, - , . , , . , . , , ; , , . . ; - - , - , , , - 3-2-4. .
, , Global Script Protection . , , cf_root/lib/neo-security.xml , cf_root/WEB-INF/cfusion/lib/neo-security.xml JEE . , ColdFusion , CrossSiteScriptPatterns.
:
<var name='CrossSiteScriptPatterns'>
<struct type='coldfusion.server.ConfigMap'>
<var name='<\s*(object|embed|script|applet|meta)'>
<string><InvalidTag</string>
</var>
</struct>
</var>
, Script , <object <embed <script <applet <meta <InvalidTag. , , .
.