Welcome Guest, Not a member yet? Register   Sign In
libraries:input:xss_clean - does a rawurldecode : this breaks some post data, and is unnecessary
#1

[eluser]Unknown[/eluser]
libraries:input:xss_clean - does a rawurldecode : this breaks some post data, and is unnecessary

I have xss_clean configured on site wide.

I understand that post (input) data is urldecoded to try and prevent url encoded domains being submitted.

However

a - this is pointless as to get around it as a hacker I just need to double url encode my attack string
b - if I have a place holder in a template being submitted called say


Messages In This Thread
libraries:input:xss_clean - does a rawurldecode : this breaks some post data, and is unnecessary - by El Forum - 05-26-2010, 07:11 AM



Theme © iAndrew 2016 - Forum software by © MyBB