|
Posted by David Dorward on 01/21/06 13:17
Greg N. wrote:
> There is a security problem with that code if the PHP page (page2.php)
> writes any data to a data base or to a flat file. It would allow a
> hacker to sneak in data you don't want or expect.
>
> If it is just your simple application that displays a picture of Mars or
> something like that, I think you don't need to be concerned.
It is a security hazard anyway, since, as I mentioned previously, should a
third party be able to persuade a user to visit the site using a suitable
crafted URL then they can execute arbitrary JavaScript with the privileges
of that domain.
--
David Dorward <http://blog.dorward.me.uk/> <http://dorward.me.uk/>
Home is where the ~/.bashrc is
Navigation:
[Reply to this message]
|