XSS Hole in PHP_SELF

This is a discussion on "XSS Hole in PHP_SELF" within the Other Programming Languages section. This forum, and the thread "XSS Hole in PHP_SELF are both part of the Program Your Website category.


 Subscribe in a reader

Go Back   Webforumz.com > Main Forums > Program Your Website > Other Programming Languages

Notices




Reply
 
LinkBack Thread Tools
  #1  
Old Mar 24th, 2008, 17:23
Junior Member
Join Date: Dec 2007
Location: UK
Posts: 31
Thanks: 0
Thanked 0 Times in 0 Posts
XSS Hole in PHP_SELF

It was brought to my attention recently by a reader of the blog that there was a vulnerability in one of my posts (The email sending script). I dismissed it becuase PHP_SELF is a server variable but then he confirmed with a proof of concept.

I think you as programmers should have a look at this. It escaped me and before coming into webdesign i was in security so I should have come across it!

http://blog.pryde-design.co.uk/2008/...e-in-php_self/

Andrew

Disclaimer: I am posting this as a contribution to the forum I would like to think that is a good one so please don't remove it just becuase its posted on my blog I have spoken to jackfranklin about my methods already.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote

  #2  
Old Mar 24th, 2008, 17:40
Jack Franklin's Avatar
Moderator

SuperMember
Join Date: May 2007
Location: Cornwall, England
Posts: 1,405
Blog Entries: 8
Thanks: 18
Thanked 14 Times in 14 Posts
Re: XSS Hole in PHP_SELF

Hi Andrew,

The way you have posted this is fine. Thank you.

And good post as well - I read it earlier
__________________
Jack Franklin - Webforumz Moderator
(x)HTML | CSS | PHP | MySQL | JQuery (Javascript)
Contact: My Blog | Twitter | Delicious
Want Lessons? PM me.
If you think I've helped, please press the 'Thanks' Button.
Last Blog Entry: A Week with VBulletin (Aug 28th, 2008)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #3  
Old Mar 24th, 2008, 17:47
Junior Member
Join Date: Dec 2007
Location: UK
Posts: 31
Thanks: 0
Thanked 0 Times in 0 Posts
Re: XSS Hole in PHP_SELF

Thankyou for both the endorsement of the post here and the post on the blog it means allot to have your support in this especially as we have disagreed in the past.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
advice about contaent managment for one hole page only vandiermen Scripts and Online Services 7 Jul 17th, 2007 13:27
Help, hole in layout kokuszka Web Page Design 4 Apr 26th, 2006 11:37
PHP form results $PHP_self is blank jamina1 PHP Forum 17 Sep 23rd, 2005 16:13


All times are GMT. The time now is 16:49.


Powered by vBulletin®
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0 RC8
© 2003-2008 Webforumz.com : All Rights Reserved

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42