PHP Developers Network

A community of PHP developers offering assistance, advice, discussion, and friendship.
 
Loading
It is currently Sat Oct 19, 2019 11:00 am

All times are UTC - 5 hours




Post new topic Reply to topic  [ 5 posts ] 
Author Message
 Post subject: XSS from the url
PostPosted: Tue Nov 15, 2011 4:27 am 
Offline
DevNet Master
User avatar

Joined: Sun Feb 15, 2009 12:08 pm
Posts: 2794
Location: .za
I did a test on an existing website with the following code for a query string page.php?id=Value<script type="text/javascript">alert('XSS')</script>. Not suprisingly it displays the alert. However, in the php code, i have the following
Syntax: [ Download ] [ Hide ]
<?php
 $value = $_GET['id'];
 // before i use it in the query
 $cleanValue = trim(htmlentities($value, ENT_QUOTES));
?>

Yet even with this, the alert message is still displayed when i load the page.

What am i missing?

_________________
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.” - Mosher’s Law of Software Engineering


Top
 Profile  
 
 Post subject: Re: XSS from the url
PostPosted: Tue Nov 15, 2011 6:18 am 
Offline
Forum Regular
User avatar

Joined: Tue Sep 28, 2010 11:41 am
Posts: 984
Location: Columbus, Ohio
what is the code where you are displaying $cleanValue?


Top
 Profile  
 
 Post subject: Re: XSS from the url
PostPosted: Tue Nov 15, 2011 6:25 am 
Offline
DevNet Master
User avatar

Joined: Sun Feb 15, 2009 12:08 pm
Posts: 2794
Location: .za
That's my problem then, the results don't use htmlentities() when i display them back to the browser 8O

_________________
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.” - Mosher’s Law of Software Engineering


Top
 Profile  
 
 Post subject: Re: XSS from the url
PostPosted: Tue Nov 15, 2011 7:27 am 
Offline
Forum Regular
User avatar

Joined: Tue Sep 28, 2010 11:41 am
Posts: 984
Location: Columbus, Ohio
Do you have any place on the page that echos out $_SERVER['PHP_SELF'] as that will also give the full URL.


Top
 Profile  
 
 Post subject: Re: XSS from the url
PostPosted: Tue Nov 15, 2011 7:33 am 
Offline
DevNet Master
User avatar

Joined: Sun Feb 15, 2009 12:08 pm
Posts: 2794
Location: .za
No but when i enter it in the URL i assume it is parsed as part of $_GET['id']; that value is displayed elsewhere on the page

_________________
“Don’t worry if it doesn’t work right. If everything did, you’d be out of a job.” - Mosher’s Law of Software Engineering


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 5 posts ] 

All times are UTC - 5 hours


Who is online

Users browsing this forum: No registered users and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group