Doc #62434 [Opn->Csd]: Bad practice escaping example in 'PHP and HTML' FAQ

From: Date: Thu, 28 Jun 2012 00:35:41 +0000
Subject: Doc #62434 [Opn->Csd]: Bad practice escaping example in 'PHP and HTML' FAQ
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-8508@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62434&edit=1 ID: 62434 Updated by: aharvey@php.net Reported by: timf at tfountain dot co dot uk Summary: Bad practice escaping example in 'PHP and HTML' FAQ -Status: Open +Status: Closed Type: Documentation Problem Package: Documentation problem PHP Version: Irrelevant -Assigned To: +Assigned To: aharvey Block user comment: N Private report: N New Comment: This bug has been fixed in the documentation's XML sources. Since the online and downloadable versions of the documentation need some time to get updated, we would like to ask you to be a bit patient. Thank you for the report, and for helping us make our documentation better. Great catch. Thanks! Previous Comments: ------------------------------------------------------------------------ [2012-06-28 00:35:34] aharvey@php.net Automatic comment from SVN on behalf of aharvey Revision: http://svn.php.net/viewvc/?view=revision&amp;revision=326363 Log: Fix doc bug #62434 (Bad practice escaping example in 'PHP and HTML' FAQ). ------------------------------------------------------------------------ [2012-06-27 18:23:03] timf at tfountain dot co dot uk Description: ------------ The very first code example in the "PHP and HTML" FAQ (http://www.php.net/manual/en/faq.html.php) includes this code sample: <?php echo "<input type='hidden' value='" . htmlspecialchars($data) . "' />\n"; ?> This code would be vulnerable to XSS if the input type was anything other than 'hidden', since the value attribute is single quoted and htmlspecialchars does not escape single quotes by default. Even the hidden input would be vulnerable in some older browsers that allow repeating the type attribute (allowing XSS with something like $data = "' onmouseover='alert(document.cookie); type='text";). Since this FAQ is meant to show users how to include PHP variables in a HTML page it would seem like a good place encourage good escaping practices. I would suggest this example is at least changed to: <?php echo '<input type="hidden" value="' . htmlspecialchars($data) . '" />'; ?> but this section of the FAQ might also benefit from some "how do I prevent cross-site scripting" examples. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=62434&edit=1

« previous php.doc.bugs (#8508) next »