mailing list archives
Re: Re: Re: Re: Mis-diagnosed XSS bugs hiding worse issues due to PHP feature
From: Jasper Bryant-Greene <jasper () album co nz>
Date: Sun, 02 Apr 2006 18:47:55 +1200
Yes like you said there is no check, because the stripslashes is a joke.
And yes this script isn't famous at all, but it was just to show a recent
example of an error in the advisory, even if this one is just a detail
Stripslashes is not a joke, it's just not designed for what its being
used for. The developer that tries to use it for input
validation/checking, now *there's* the joke!
http://www.album.co.nz/ 0800 4 ALBUM
jasper () album co nz 021 708 334
Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia - http://secunia.com/