You accept input from the user and do not sanitize it, and then print it out.
Don't do that.
Either do not print the user input at all, or check that the user input is well-formed before you print it, or escape it before printing.
If you think you want to escape the user input, you need to specify what the output target is. Escaping for the console window is different from escaping for a browser.
In reply to Re: Reflected XSS All Clients
by Corion
in thread Reflected XSS All Clients
by Rishi2Monk
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |