This is a discussion on "XSS Hole in PHP_SELF" within the Other Programming Languages section. This forum, and the thread "XSS Hole in PHP_SELF are both part of the Program Your Website category.
|
|
|
|
|
![]() |
||
XSS Hole in PHP_SELF
|
||
| Notices |
![]() |
|
|
LinkBack | Thread Tools |
|
#1
|
|||
|
|||
|
XSS Hole in PHP_SELF
It was brought to my attention recently by a reader of the blog that there was a vulnerability in one of my posts (The email sending script). I dismissed it becuase PHP_SELF is a server variable but then he confirmed with a proof of concept.
I think you as programmers should have a look at this. It escaped me and before coming into webdesign i was in security so I should have come across it! http://blog.pryde-design.co.uk/2008/...e-in-php_self/ Andrew Disclaimer: I am posting this as a contribution to the forum I would like to think that is a good one so please don't remove it just becuase its posted on my blog I have spoken to jackfranklin about my methods already. |
|
|
|
#2
|
||||
|
||||
|
Re: XSS Hole in PHP_SELF
Hi Andrew,
The way you have posted this is fine. Thank you. And good post as well - I read it earlier
__________________
Jack Franklin - Webforumz Moderator (x)HTML | CSS | PHP | MySQL | JQuery (Javascript) Contact: My Blog | Twitter | Delicious Want Lessons? PM me. If you think I've helped, please press the 'Thanks' Button.
Last Blog Entry: A Week with VBulletin (Aug 28th, 2008)
|
|
#3
|
|||
|
|||
|
Re: XSS Hole in PHP_SELF
Thankyou for both the endorsement of the post here and the post on the blog it means allot to have your support in this especially as we have disagreed in the past.
|
![]() |
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| advice about contaent managment for one hole page only | vandiermen | Scripts and Online Services | 7 | Jul 17th, 2007 13:27 |
| Help, hole in layout | kokuszka | Web Page Design | 4 | Apr 26th, 2006 11:37 |
| PHP form results $PHP_self is blank | jamina1 | PHP Forum | 17 | Sep 23rd, 2005 16:13 |