Doc #62434 [NEW]: Bad practice escaping example in 'PHP and HTML' FAQ

From: Date: Wed, 27 Jun 2012 18:23:03 +0000
Subject: Doc #62434 [NEW]: Bad practice escaping example in 'PHP and HTML' FAQ
Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-8507@lists.php.net to get a copy of this message
From: timf at tfountain dot co dot uk Operating system: PHP version: Irrelevant Package: Documentation problem Bug Type: Documentation Problem Bug description:Bad practice escaping example in 'PHP and HTML' FAQ Description: ------------ The very first code example in the "PHP and HTML" FAQ (http://www.php.net/manual/en/faq.html.php) includes this code sample: <?php echo "<input type='hidden' value='" . htmlspecialchars($data) . "' />\n"; ?> This code would be vulnerable to XSS if the input type was anything other than 'hidden', since the value attribute is single quoted and htmlspecialchars does not escape single quotes by default. Even the hidden input would be vulnerable in some older browsers that allow repeating the type attribute (allowing XSS with something like $data = "' onmouseover='alert(document.cookie); type='text";). Since this FAQ is meant to show users how to include PHP variables in a HTML page it would seem like a good place encourage good escaping practices. I would suggest this example is at least changed to: <?php echo '<input type="hidden" value="' . htmlspecialchars($data) . '" />'; ?> but this section of the FAQ might also benefit from some "how do I prevent cross-site scripting" examples. -- Edit bug report at https://bugs.php.net/bug.php?id=62434&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=62434&r=trysnapshot54 Try a snapshot (PHP 5.3): https://bugs.php.net/fix.php?id=62434&r=trysnapshot53 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=62434&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=62434&r=fixed Fixed in SVN and need be documented: https://bugs.php.net/fix.php?id=62434&r=needdocs Fixed in release: https://bugs.php.net/fix.php?id=62434&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=62434&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=62434&r=needscript Try newer version: https://bugs.php.net/fix.php?id=62434&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=62434&r=support Expected behavior: https://bugs.php.net/fix.php?id=62434&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=62434&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=62434&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=62434&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=62434&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=62434&r=dst IIS Stability: https://bugs.php.net/fix.php?id=62434&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=62434&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=62434&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=62434&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=62434&r=mysqlcfg

« previous php.doc.bugs (#8507) next »