Doc #62434 [NEW]: Bad practice escaping example in 'PHP and HTML' FAQ
| From: | timf at tfountain dot co dot uk | Date: | Wed, 27 Jun 2012 18:23:03 +0000 |
| Subject: | Doc #62434 [NEW]: Bad practice escaping example in 'PHP and HTML' FAQ | ||
| Groups: | php.doc.bugs | ||
| Request: | Send a blank email to doc-bugs+get-8507@lists.php.net to get a copy of this message | ||
From: timf at tfountain dot co dot uk
Operating system:
PHP version: Irrelevant
Package: Documentation problem
Bug Type: Documentation Problem
Bug description:Bad practice escaping example in 'PHP and HTML' FAQ
Description:
------------
The very first code example in the "PHP and HTML" FAQ
(http://www.php.net/manual/en/faq.html.php) includes this code sample:
<?php
echo "<input type='hidden' value='" . htmlspecialchars($data) .
"'
/>\n";
?>
This code would be vulnerable to XSS if the input type was anything other
than
'hidden', since the value attribute is single quoted and htmlspecialchars
does
not escape single quotes by default. Even the hidden input would be
vulnerable
in some older browsers that allow repeating the type attribute (allowing
XSS
with something like $data = "' onmouseover='alert(document.cookie);
type='text";).
Since this FAQ is meant to show users how to include PHP variables in a
HTML
page it would seem like a good place encourage good escaping practices. I
would
suggest this example is at least changed to:
<?php
echo '<input type="hidden" value="' . htmlspecialchars($data) .
'"
/>';
?>
but this section of the FAQ might also benefit from some "how do I prevent
cross-site scripting" examples.
--
Edit bug report at https://bugs.php.net/bug.php?id=62434&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=62434&r=trysnapshot54
Try a snapshot (PHP 5.3): https://bugs.php.net/fix.php?id=62434&r=trysnapshot53
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=62434&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=62434&r=fixed
Fixed in SVN and need be documented: https://bugs.php.net/fix.php?id=62434&r=needdocs
Fixed in release: https://bugs.php.net/fix.php?id=62434&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=62434&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=62434&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=62434&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=62434&r=support
Expected behavior: https://bugs.php.net/fix.php?id=62434&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=62434&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=62434&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=62434&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=62434&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=62434&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=62434&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=62434&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=62434&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=62434&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=62434&r=mysqlcfg