{"id":401,"date":"2010-02-23T20:30:16","date_gmt":"2010-02-24T02:30:16","guid":{"rendered":"http:\/\/www.webadminblog.com\/?p=401"},"modified":"2010-02-23T20:32:14","modified_gmt":"2010-02-24T02:32:14","slug":"a-xss-vulnerability-in-almost-every-php-form-ive-ever-written","status":"publish","type":"post","link":"https:\/\/www.webadminblog.com\/index.php\/2010\/02\/23\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\/","title":{"rendered":"A XSS Vulnerability in Almost Every PHP Form I&#8217;ve Ever Written"},"content":{"rendered":"<p>I&#8217;ve spent a lot of time over the past few months writing an enterprise application in PHP.\u00a0 Despite what some people may say, I believe that PHP is as secure or insecure as the developer who is writing the code.\u00a0 Anyway, I&#8217;m at the point in my development lifecycle where I decided that it was ready to run an application vulnerability scanner against it.\u00a0 What I found was interesting and I think it&#8217;s worth sharing with you all.<\/p>\n<p>Let me preface this by saying that I&#8217;m the guy who gives the training to our developers on the OWASP Top 10, writing secure code, etc.\u00a0 I&#8217;d like to think that I have a pretty good handle on programming best practices, input validation, and HTML encoding.\u00a0 I built all kinds of validation into this application and thought that the vulnerability scan would come up empty.\u00a0 For the most part I was right, but there was one vulnerability, one flaw in particular, that found it&#8217;s way into every form in my application.\u00a0 In fact, I realized that I&#8217;ve made this exact same mistake in almost every PHP form that I&#8217;ve ever written.\u00a0 Talk about a humbling experience.<\/p>\n<p>So here&#8217;s what happened.\u00a0 I created a simple page with a form where the results of that form are submitted back to the page itself for processing.\u00a0 Let&#8217;s assume it looks something like this:<\/p>\n<pre>&lt;<a href=\"http:\/\/december.com\/html\/4\/element\/html.html\">html<\/a>&gt;\r\n &lt;<a href=\"http:\/\/december.com\/html\/4\/element\/body.html\">body<\/a>&gt;\r\n  &lt;?php\r\n  if (isset($_REQUEST['submitted']) &amp;&amp; $_REQUEST['submitted'] == '1') {\r\n    echo \"Form submitted!\";\r\n  }\r\n  ?&gt;\r\n  &lt;<a href=\"http:\/\/december.com\/html\/4\/element\/form.html\">form<\/a> action=\"&lt;?php echo $_SERVER['PHP_SELF']; ?&gt;\"&gt;\r\n   &lt;<a href=\"http:\/\/december.com\/html\/4\/element\/input.html\">input<\/a> type=\"hidden\" name=\"submitted\" value=\"1\" \/&gt;\r\n   &lt;<a href=\"http:\/\/december.com\/html\/4\/element\/input.html\">input<\/a> type=\"submit\" value=\"Submit!\" \/&gt;\r\n  &lt;\/<a href=\"http:\/\/december.com\/html\/4\/element\/form.html\">form<\/a>&gt;\r\n &lt;\/<a href=\"http:\/\/december.com\/html\/4\/element\/body.html\">body<\/a>&gt;\r\n&lt;\/<a href=\"http:\/\/december.com\/html\/4\/element\/html.html\">html<\/a>&gt;\r\n<\/pre>\n<p>It looks fairly straightforward, right?  The problem has to do with that $_SERVER[&#8216;PHP_SELF&#8217;] variable.  The intent here is that PHP will display the path and name of the current page so that the form knows to submit back to the same page.\u00a0 The problem is that $_SERVER[&#8216;PHP_SELF&#8217;] can actually be manipulated by the user.\u00a0 Let&#8217;s say as the user I change the URL from https:\/\/www.webadminblog.com\/example.php to https:\/\/www.webadminblog.com\/example.php&#8221;&gt;&lt;script&gt;alert(&#8216;xss&#8217;);&lt;\/script&gt;.\u00a0 This will end the form action part of the code and inject a javascript alert into the page.\u00a0 This is the very definition of cross site scripting.\u00a0 I can&#8217;t believe that with as long as I&#8217;ve been writing in PHP and as  long as I&#8217;ve been studying application security, I&#8217;ve never realized this.\u00a0 Fortunately, there are a couple of different ways to fix this.\u00a0 First, you could use the HTML entities or HTML special character functions to sanitize the user input like this:<\/p>\n<p>htmlentities($_SERVER[&#8216;PHP_SELF]);<\/p>\n<p>htmlspecialchars($_SERVER[&#8216;PHP_SELF]);<\/p>\n<p>This fix would still allow the user to manipulate the URL, and thus, what is displayed on the page, but it would render the javascript invalid.\u00a0 The second way to fix this is to use the script name variable instead like this:<\/p>\n<p>$_SERVER[&#8216;SCRIPT_NAME&#8217;];<\/p>\n<p>This fix would just echo the full path and filename of the current file.\u00a0\u00a0\u00a0 Yes, there are other ways to fix this.\u00a0 Yes, my code example above for the XSS exploit doesn&#8217;t do anything other than display a javascript alert.\u00a0 I just wanted to draw attention to this issue because if it&#8217;s found it&#8217;s way into my code, then perhaps it&#8217;s found it&#8217;s way into yours as well.\u00a0 Happy coding!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I&#8217;ve spent a lot of time over the past few months writing an enterprise application in PHP.\u00a0 Despite what some people may say, I believe that PHP is as secure or insecure as the developer who is writing the code.\u00a0 Anyway, I&#8217;m at the point in my development lifecycle where I decided that it was [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[4],"tags":[175,396,395,161,393,394,177,176,10,174],"class_list":["post-401","post","type-post","status-publish","format-standard","hentry","category-web-app-sec","tag-cross","tag-cross-site","tag-form","tag-php","tag-php_self","tag-post","tag-scripting","tag-site","tag-vulnerability","tag-xss"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"I&#039;ve spent a lot of time over the past few months writing an enterprise application in PHP. Despite what some people may say, I believe that PHP is as secure or insecure as the developer who is writing the code. Anyway, I&#039;m at the point in my development lifecycle where I decided that it was\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Josh\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.webadminblog.com\/index.php\/2010\/02\/23\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Web Admin Blog | Real Web Admins.  Real World Experience.\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"A XSS Vulnerability in Almost Every PHP Form I\u2019ve Ever Written | Web Admin Blog\" \/>\n\t\t<meta property=\"og:description\" content=\"I&#039;ve spent a lot of time over the past few months writing an enterprise application in PHP. Despite what some people may say, I believe that PHP is as secure or insecure as the developer who is writing the code. Anyway, I&#039;m at the point in my development lifecycle where I decided that it was\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.webadminblog.com\/index.php\/2010\/02\/23\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2010-02-24T02:30:16+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2010-02-24T02:32:14+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"A XSS Vulnerability in Almost Every PHP Form I\u2019ve Ever Written | Web Admin Blog\" \/>\n\t\t<meta name=\"twitter:description\" content=\"I&#039;ve spent a lot of time over the past few months writing an enterprise application in PHP. Despite what some people may say, I believe that PHP is as secure or insecure as the developer who is writing the code. Anyway, I&#039;m at the point in my development lifecycle where I decided that it was\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/2010\\\/02\\\/23\\\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\\\/#article\",\"name\":\"A XSS Vulnerability in Almost Every PHP Form I\\u2019ve Ever Written | Web Admin Blog\",\"headline\":\"A XSS Vulnerability in Almost Every PHP Form I&#8217;ve Ever Written\",\"author\":{\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/author\\\/jsokol\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/#organization\"},\"datePublished\":\"2010-02-23T20:30:16-06:00\",\"dateModified\":\"2010-02-23T20:32:14-06:00\",\"inLanguage\":\"en-US\",\"commentCount\":30,\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/2010\\\/02\\\/23\\\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/2010\\\/02\\\/23\\\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\\\/#webpage\"},\"articleSection\":\"Web Application Security, cross, cross-site, form, php, php_self, post, scripting, site, vulnerability, xss\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/2010\\\/02\\\/23\\\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.webadminblog.com#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.webadminblog.com\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/category\\\/security\\\/#listItem\",\"name\":\"Security\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/category\\\/security\\\/#listItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/category\\\/security\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/category\\\/security\\\/web-app-sec\\\/#listItem\",\"name\":\"Web Application Security\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.webadminblog.com#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/category\\\/security\\\/web-app-sec\\\/#listItem\",\"position\":3,\"name\":\"Web Application Security\",\"item\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/category\\\/security\\\/web-app-sec\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/2010\\\/02\\\/23\\\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\\\/#listItem\",\"name\":\"A XSS Vulnerability in Almost Every PHP Form I&#8217;ve Ever Written\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/category\\\/security\\\/#listItem\",\"name\":\"Security\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/2010\\\/02\\\/23\\\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\\\/#listItem\",\"position\":4,\"name\":\"A XSS Vulnerability in Almost Every PHP Form I&#8217;ve Ever Written\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/category\\\/security\\\/web-app-sec\\\/#listItem\",\"name\":\"Web Application Security\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/#organization\",\"name\":\"Web Admin Blog\",\"description\":\"Real Web Admins.  Real World Experience.\",\"url\":\"https:\\\/\\\/www.webadminblog.com\\\/\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/author\\\/jsokol\\\/#author\",\"url\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/author\\\/jsokol\\\/\",\"name\":\"Josh\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/2010\\\/02\\\/23\\\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/b9a6f9a4045419aaa65743aba583ce8c1b6d6d7789e949e44c9853914aecf2e9?s=96&d=identicon&r=pg\",\"width\":96,\"height\":96,\"caption\":\"Josh\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/2010\\\/02\\\/23\\\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\\\/#webpage\",\"url\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/2010\\\/02\\\/23\\\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\\\/\",\"name\":\"A XSS Vulnerability in Almost Every PHP Form I\\u2019ve Ever Written | Web Admin Blog\",\"description\":\"I've spent a lot of time over the past few months writing an enterprise application in PHP. Despite what some people may say, I believe that PHP is as secure or insecure as the developer who is writing the code. Anyway, I'm at the point in my development lifecycle where I decided that it was\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/2010\\\/02\\\/23\\\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/author\\\/jsokol\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/index.php\\\/author\\\/jsokol\\\/#author\"},\"datePublished\":\"2010-02-23T20:30:16-06:00\",\"dateModified\":\"2010-02-23T20:32:14-06:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/#website\",\"url\":\"https:\\\/\\\/www.webadminblog.com\\\/\",\"name\":\"Web Admin Blog\",\"description\":\"Real Web Admins.  Real World Experience.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.webadminblog.com\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"A XSS Vulnerability in Almost Every PHP Form I\u2019ve Ever Written | Web Admin Blog","description":"I've spent a lot of time over the past few months writing an enterprise application in PHP. Despite what some people may say, I believe that PHP is as secure or insecure as the developer who is writing the code. Anyway, I'm at the point in my development lifecycle where I decided that it was","canonical_url":"https:\/\/www.webadminblog.com\/index.php\/2010\/02\/23\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.webadminblog.com\/index.php\/2010\/02\/23\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\/#article","name":"A XSS Vulnerability in Almost Every PHP Form I\u2019ve Ever Written | Web Admin Blog","headline":"A XSS Vulnerability in Almost Every PHP Form I&#8217;ve Ever Written","author":{"@id":"https:\/\/www.webadminblog.com\/index.php\/author\/jsokol\/#author"},"publisher":{"@id":"https:\/\/www.webadminblog.com\/#organization"},"datePublished":"2010-02-23T20:30:16-06:00","dateModified":"2010-02-23T20:32:14-06:00","inLanguage":"en-US","commentCount":30,"mainEntityOfPage":{"@id":"https:\/\/www.webadminblog.com\/index.php\/2010\/02\/23\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\/#webpage"},"isPartOf":{"@id":"https:\/\/www.webadminblog.com\/index.php\/2010\/02\/23\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\/#webpage"},"articleSection":"Web Application Security, cross, cross-site, form, php, php_self, post, scripting, site, vulnerability, xss"},{"@type":"BreadcrumbList","@id":"https:\/\/www.webadminblog.com\/index.php\/2010\/02\/23\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.webadminblog.com#listItem","position":1,"name":"Home","item":"https:\/\/www.webadminblog.com","nextItem":{"@type":"ListItem","@id":"https:\/\/www.webadminblog.com\/index.php\/category\/security\/#listItem","name":"Security"}},{"@type":"ListItem","@id":"https:\/\/www.webadminblog.com\/index.php\/category\/security\/#listItem","position":2,"name":"Security","item":"https:\/\/www.webadminblog.com\/index.php\/category\/security\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.webadminblog.com\/index.php\/category\/security\/web-app-sec\/#listItem","name":"Web Application Security"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.webadminblog.com#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.webadminblog.com\/index.php\/category\/security\/web-app-sec\/#listItem","position":3,"name":"Web Application Security","item":"https:\/\/www.webadminblog.com\/index.php\/category\/security\/web-app-sec\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.webadminblog.com\/index.php\/2010\/02\/23\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\/#listItem","name":"A XSS Vulnerability in Almost Every PHP Form I&#8217;ve Ever Written"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.webadminblog.com\/index.php\/category\/security\/#listItem","name":"Security"}},{"@type":"ListItem","@id":"https:\/\/www.webadminblog.com\/index.php\/2010\/02\/23\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\/#listItem","position":4,"name":"A XSS Vulnerability in Almost Every PHP Form I&#8217;ve Ever Written","previousItem":{"@type":"ListItem","@id":"https:\/\/www.webadminblog.com\/index.php\/category\/security\/web-app-sec\/#listItem","name":"Web Application Security"}}]},{"@type":"Organization","@id":"https:\/\/www.webadminblog.com\/#organization","name":"Web Admin Blog","description":"Real Web Admins.  Real World Experience.","url":"https:\/\/www.webadminblog.com\/"},{"@type":"Person","@id":"https:\/\/www.webadminblog.com\/index.php\/author\/jsokol\/#author","url":"https:\/\/www.webadminblog.com\/index.php\/author\/jsokol\/","name":"Josh","image":{"@type":"ImageObject","@id":"https:\/\/www.webadminblog.com\/index.php\/2010\/02\/23\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/b9a6f9a4045419aaa65743aba583ce8c1b6d6d7789e949e44c9853914aecf2e9?s=96&d=identicon&r=pg","width":96,"height":96,"caption":"Josh"}},{"@type":"WebPage","@id":"https:\/\/www.webadminblog.com\/index.php\/2010\/02\/23\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\/#webpage","url":"https:\/\/www.webadminblog.com\/index.php\/2010\/02\/23\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\/","name":"A XSS Vulnerability in Almost Every PHP Form I\u2019ve Ever Written | Web Admin Blog","description":"I've spent a lot of time over the past few months writing an enterprise application in PHP. Despite what some people may say, I believe that PHP is as secure or insecure as the developer who is writing the code. Anyway, I'm at the point in my development lifecycle where I decided that it was","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.webadminblog.com\/#website"},"breadcrumb":{"@id":"https:\/\/www.webadminblog.com\/index.php\/2010\/02\/23\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\/#breadcrumblist"},"author":{"@id":"https:\/\/www.webadminblog.com\/index.php\/author\/jsokol\/#author"},"creator":{"@id":"https:\/\/www.webadminblog.com\/index.php\/author\/jsokol\/#author"},"datePublished":"2010-02-23T20:30:16-06:00","dateModified":"2010-02-23T20:32:14-06:00"},{"@type":"WebSite","@id":"https:\/\/www.webadminblog.com\/#website","url":"https:\/\/www.webadminblog.com\/","name":"Web Admin Blog","description":"Real Web Admins.  Real World Experience.","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.webadminblog.com\/#organization"}}]},"og:locale":"en_US","og:site_name":"Web Admin Blog | Real Web Admins.  Real World Experience.","og:type":"article","og:title":"A XSS Vulnerability in Almost Every PHP Form I\u2019ve Ever Written | Web Admin Blog","og:description":"I've spent a lot of time over the past few months writing an enterprise application in PHP. Despite what some people may say, I believe that PHP is as secure or insecure as the developer who is writing the code. Anyway, I'm at the point in my development lifecycle where I decided that it was","og:url":"https:\/\/www.webadminblog.com\/index.php\/2010\/02\/23\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\/","article:published_time":"2010-02-24T02:30:16+00:00","article:modified_time":"2010-02-24T02:32:14+00:00","twitter:card":"summary_large_image","twitter:title":"A XSS Vulnerability in Almost Every PHP Form I\u2019ve Ever Written | Web Admin Blog","twitter:description":"I've spent a lot of time over the past few months writing an enterprise application in PHP. Despite what some people may say, I believe that PHP is as secure or insecure as the developer who is writing the code. Anyway, I'm at the point in my development lifecycle where I decided that it was"},"aioseo_meta_data":{"post_id":"401","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2025-01-03 22:47:31","updated":"2025-07-17 07:16:27","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.webadminblog.com\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.webadminblog.com\/index.php\/category\/security\/\" title=\"Security\">Security<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.webadminblog.com\/index.php\/category\/security\/web-app-sec\/\" title=\"Web Application Security\">Web Application Security<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tA XSS Vulnerability in Almost Every PHP Form I\u2019ve Ever Written\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.webadminblog.com"},{"label":"Security","link":"https:\/\/www.webadminblog.com\/index.php\/category\/security\/"},{"label":"Web Application Security","link":"https:\/\/www.webadminblog.com\/index.php\/category\/security\/web-app-sec\/"},{"label":"A XSS Vulnerability in Almost Every PHP Form I&#8217;ve Ever Written","link":"https:\/\/www.webadminblog.com\/index.php\/2010\/02\/23\/a-xss-vulnerability-in-almost-every-php-form-ive-ever-written\/"}],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/posts\/401","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/comments?post=401"}],"version-history":[{"count":7,"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/posts\/401\/revisions"}],"predecessor-version":[{"id":481,"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/posts\/401\/revisions\/481"}],"wp:attachment":[{"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/media?parent=401"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/categories?post=401"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/tags?post=401"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}