in reply to Re: Reflected XSS All Clients
in thread Reflected XSS All Clients

Thanks for the reply. I corrected the compilation and /[^0-9]/. My intension is to clear the cleckmarx and since I do not know the content of the input, I go with print instead of die. But even after I do this sanitization, Checkmarx is not satified and throw the same error

Replies are listed 'Best First'.
Re^3: Reflected XSS All Clients
by Corion (Patriarch) on Dec 27, 2022 at 10:27 UTC

    You are still not escaping the user specified values for your output target format. Until you do that, you will not solve the problem.

    A reply falls below the community's threshold of quality. You may see it by logging in.