Jump to content

Form validation: What dangerous characters should I look for?


MrCat

Recommended Posts

Hi. I have a site where people can post photos and also captions for the photos.

I'm saving the captions in simple text files for including with the HTML. Of course, I don't want someone to put "<script>" in a caption input form, but what else should I filter out?

Is it enough just to destroy all instances of "<"? I want to give people the freedom to include brackets and hyphens etc if possible.

Any ideas appreciated!

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.