note 72493 added to function.strftime
| From: | judas dot iscariote at gmail dot com | Date: | Sun, 21 Jan 2007 08:34:02 +0000 |
| Subject: | note 72493 added to function.strftime | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-121977@lists.php.net to get a copy of this message | ||
Security notice:
You can end with a (probably unexpected) XSS if the $format parameter is user submitted data ;)
<?php
echo strftime("<script>alert('lol');</script>");
?>
PHP does not check if $format is a valid format, so the usual security precautions should be taken
here .
----
Server IP: 200.24.234.70
Probable Submitter: 200.7.26.140
----
Manual Page -- http://www.php.net/manual/en/function.strftime.php
Edit -- https://master.php.net/note/edit/72493
Del: integrated -- https://master.php.net/note/delete/72493/integrated
Del: useless -- https://master.php.net/note/delete/72493/useless
Del: bad code -- https://master.php.net/note/delete/72493/bad+code
Del: spam -- https://master.php.net/note/delete/72493/spam
Del: non-english -- https://master.php.net/note/delete/72493/non-english
Del: in docs -- https://master.php.net/note/delete/72493/in+docs
Del: other reasons-- https://master.php.net/note/delete/72493
Reject -- https://master.php.net/note/reject/72493
Search -- https://master.php.net/manage/user-notes.php