Full Disclosure mailing list archives
Re: Re: Re: Re: Mis-diagnosed XSS bugs hiding worse issues due to PHP feature
From: Jasper Bryant-Greene <jasper () album co nz>
Date: Sun, 02 Apr 2006 18:47:55 +1200
Siegfried wrote:
Yes like you said there is no check, because the stripslashes is a joke. And yes this script isn't famous at all, but it was just to show a recent example of an error in the advisory, even if this one is just a detail
Stripslashes is not a joke, it's just not designed for what its being used for. The developer that tries to use it for input validation/checking, now *there's* the joke!
-- Jasper Bryant-Greene General Manager Album Limited http://www.album.co.nz/ 0800 4 ALBUM jasper () album co nz 021 708 334 _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Re: Re: Re: Mis-diagnosed XSS bugs hiding worse issues due to PHP feature Siegfried (Apr 01)
- Re: Re: Re: Re: Mis-diagnosed XSS bugs hiding worse issues due to PHP feature Jasper Bryant-Greene (Apr 01)