security in guest book and user forums

From: Date: Sat, 04 Jan 2003 17:16:02 +0000
Subject: security in guest book and user forums
Groups: php.general 
Request: Send a blank email to php-general+get-130232@lists.php.net to get a copy of this message
I've seen both guest books and user forums "hacked" by users who enter javascript or other code, and that way redirects vistors to other sites or do other unwelcome things. What expressions should I look for and not allow in my forms? Best regards, Anders

« previous php.general (#130232) next »