Doc #62434 [Opn->Csd]: Bad practice escaping example in 'PHP and HTML' FAQ
| From: | aharvey@php.net | Date: | Thu, 28 Jun 2012 00:35:41 +0000 |
| Subject: | Doc #62434 [Opn->Csd]: Bad practice escaping example in 'PHP and HTML' FAQ | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-8508@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=62434&edit=1
ID: 62434
Updated by: aharvey@php.net
Reported by: timf at tfountain dot co dot uk
Summary: Bad practice escaping example in 'PHP and HTML' FAQ
-Status: Open
+Status: Closed
Type: Documentation Problem
Package: Documentation problem
PHP Version: Irrelevant
-Assigned To:
+Assigned To: aharvey
Block user comment: N
Private report: N
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation better.
Great catch. Thanks!
Previous Comments:
------------------------------------------------------------------------
[2012-06-28 00:35:34] aharvey@php.net
Automatic comment from SVN on behalf of aharvey
Revision: http://svn.php.net/viewvc/?view=revision&revision=326363
Log: Fix doc bug #62434 (Bad practice escaping example in 'PHP and HTML' FAQ).
------------------------------------------------------------------------
[2012-06-27 18:23:03] timf at tfountain dot co dot uk
Description:
------------
The very first code example in the "PHP and HTML" FAQ
(http://www.php.net/manual/en/faq.html.php) includes this code sample:
<?php
echo "<input type='hidden' value='" . htmlspecialchars($data) .
"' />\n";
?>
This code would be vulnerable to XSS if the input type was anything other than
'hidden', since the value attribute is single quoted and htmlspecialchars does
not escape single quotes by default. Even the hidden input would be vulnerable
in some older browsers that allow repeating the type attribute (allowing XSS
with something like $data = "' onmouseover='alert(document.cookie);
type='text";).
Since this FAQ is meant to show users how to include PHP variables in a HTML
page it would seem like a good place encourage good escaping practices. I would
suggest this example is at least changed to:
<?php
echo '<input type="hidden" value="' . htmlspecialchars($data) .
'" />';
?>
but this section of the FAQ might also benefit from some "how do I prevent
cross-site scripting" examples.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=62434&edit=1