homers Posted October 18, 2009 Report Share Posted October 18, 2009 Tatad vakar kaut kāds da*nis, ielika video sarkastā šadu skriptu <script>alert("xss")</script> Kā insertā var aizliegt ievietot šadus tekstus? Lai saraksta nemestu alertu. Quote Link to comment Share on other sites More sharing options...
waplet Posted October 18, 2009 Report Share Posted October 18, 2009 htmlspecialchars() vai preg_replace() Quote Link to comment Share on other sites More sharing options...
briedis Posted October 18, 2009 Report Share Posted October 18, 2009 Būtu labāk teicis paldies tam daunim, ka norādīja uz acīmredzamu ievainojamību :) Quote Link to comment Share on other sites More sharing options...
homers Posted October 18, 2009 Author Report Share Posted October 18, 2009 No vienas puses jā, bet no otras nē. Quote Link to comment Share on other sites More sharing options...
waplet Posted October 18, 2009 Report Share Posted October 18, 2009 Kāpēc nē.. tik pat labi kāds tevi vareja izownot caur to xss tā kārtīgāk :)) Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.