note 96356 deleted from reserved.variables.server by cmb
| From: | cmb@php.net | Date: | Sun, 24 Mar 2019 11:23:09 +0000 |
| Subject: | note 96356 deleted from reserved.variables.server by cmb | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-210450@lists.php.net to get a copy of this message | ||
Note Submitter: Megan Mickelson
----
It makes sense to want to paste the $_SERVER['REQUEST_URI'] on to a page (like on a
footer), but be sure to clean it up first with htmlspecialchars() otherwise it poses a cross-site
scripting vulnerability.
htmlspecialchars($_SERVER['REQUEST_URI']);
e.g.
http://www.example.com/foo?<script>...
becomes
http://www.example.com/foo?<script>...