Jump to content

[SOLVED] Fixing XSS ?


thryb

Recommended Posts

Hi guys,

Lets say there is a xss vuln in my script at

http://www.domain.com/file/"><marquee><h1>vulnerable

How can I fix it ? I have no trouble with fixing the one that affect a variable ie file.php?var=xxx

But how do I fix the one right at the end of a file like the one up here? I dont get the /">.

 

Thanks in advance!

 

Link to comment
https://forums.phpfreaks.com/topic/76088-solved-fixing-xss/
Share on other sites

Simple

 

Wherever you echo/print user submitted data, just be sure to escape it with something like htmlspecialchars

 

So instead of echo $_GET['variable']; do echo htmlspecialchars($_GET['variable']);

 

This also applies to $_POST and $_SERVER and data retrieved from databases (if people can put stuff into the database, such as in a forum system for example).

Link to comment
https://forums.phpfreaks.com/topic/76088-solved-fixing-xss/#findComment-385738
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.