Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Simple GuestBook
#7
(12-22-2009, 07:57 AM)Spl3en Wrote: Nice script Smile !

But, be careful !
When you display the messages, don't forget htmlentities !
You will be victim of XSS if you don't use that.

PS : You can concatenate string and variables like this, if you want :
PHP Code:
fwrite($file$name ": " $message "<br><br>"); 

Thanks, I was looking for ways to fix xss exploits
Reply


Messages In This Thread
Simple GuestBook - by nevets04 - 12-21-2009, 07:16 PM
RE: Simple GuestBook - by Gaijin - 12-21-2009, 07:35 PM
RE: Simple GuestBook - by nevets04 - 12-21-2009, 11:32 PM
RE: Simple GuestBook - by Gaijin - 12-21-2009, 11:47 PM
RE: Simple GuestBook - by nevets04 - 12-22-2009, 12:20 AM
RE: Simple GuestBook - by Spl3en - 12-22-2009, 07:57 AM
RE: Simple GuestBook - by nevets04 - 12-22-2009, 03:08 PM
RE: Simple GuestBook - by Socrates - 12-22-2009, 07:49 PM

Forum Jump:


Users browsing this thread: 7 Guest(s)