I have to maintain an old cgi application that for whatever reason the boss doesn't want to upgrade to a modern frame work. The dilemma is we got hit my a security scan and we are susceptible to xss attacks. How do I protect against that in cgi. What I have done so far to curb the bleeding is I've added a regex to top of script that looks for words in url script, onload,cookie,mouse,document and a few others that I will never use in the url. But that is just a stop gap. Is there anything I can further do to protect against this attack.
but that doesn't work. Any help would be appreciated.