php - how to prevent cross site scripting - Image is linked -


xss

enter image description here

can me thid cross site scripting new in this

cross-site scripting code injection attack.

the problem user (or else) enters script instead of input value. example, user puts "<script>" tag in comment.

if display list of comments, script executed visiting page.

what need sanitize outputs, is, remove or escape html code you're writing on page. way, <script> tag replaced &lt;script&gt;, , become harmless while looking same.


Comments

Popular posts from this blog

sql - invalid in the select list because it is not contained in either an aggregate function -

Angularjs unit testing - ng-disabled not working when adding text to textarea -

How to start daemon on android by adb -