security in guest book and user forums
| From: | Anders Thoresson | Date: | Sat, 04 Jan 2003 17:16:02 +0000 |
| Subject: | security in guest book and user forums | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-130232@lists.php.net to get a copy of this message | ||
I've seen both guest books and user forums "hacked" by users who enter javascript or other code, and that way redirects vistors to other sites or do other unwelcome things. What expressions should I look for and not allow in my forms?
Best regards,
Anders