3 ms·
I can't find a use case for the example the article is working with. Who in their right mind would take user input and put it in an HTML attribute? If your sy
by leviathan 15y ago
I can't find a use case for the example the article is working with.
Who in their right mind would take user input and put it in an HTML attribute?
If your system accepts 'foo" onmouseover="alert(1)' as a username, you've got bigger problems.
- pornel 15y ago> If your system accepts 'foo" onmouseover="alert(1)' as a username, you've got bigger problems. Technically that shouldn't be a problem. I can put that in HTML, in URL, in the database. I can even make directory with that name and use it in shell scripts — as long as every one of them uses correct escaping. Bobby Tables is welcome on my systems.
- olavk 15y ago> Who in their right mind would take user input and put it in an HTML attribute? Hacker news for example :) HN allows you to enter a color code in your preferences, which is inserted as a bgcolor attribute on a html table.
- rgrove 15y agoThe example I gave in the blog post was a real-world example: a link to a user's profile page that includes the username in the URL. This is extremely common. Naturally, only a fool would allow usernames to contain unsafe characters, but there are a lot of fools writing web apps.