php: xss

aside from sql injections, the next most popular security exploit is cross site scripting or xss. while sql injections deal with how data is inputed to the database xss deals with how data is outputted from the database. while a good "cleaning" function (which parses data to be inputed into the database) could prevent both sql injections and xss, most do not. xss occures when a piece of functioning code is stored in a database and displayed by simply echoing it.

Author: CodeCall Programming Forum

  • September 23, 2007 11:12 pm
