Welcome Guest, Not a member yet? Register   Sign In
4.4.1 to 4.4.8 base_url php spark closes..
#5

(This post was last modified: 05-09-2024, 06:21 AM by xsPurX.)

(05-09-2024, 05:36 AM)kenjis Wrote: I forgot to mention that the above code is vulnerable because it does not validate the value of $_SERVER['HTTP_HOST'].
In a production environment, all user input should be validated.

Can you elborate on that? what would be a way to validate it. I thought that comes from the server end. If they change the domain name, it wouldn't load my site it would load a different site? It's not entered anywhere so I don't understand how this would be considered user input?
Reply


Messages In This Thread
RE: 4.4.1 to 4.4.8 base_url php spark closes.. - by xsPurX - 05-09-2024, 06:21 AM



Theme © iAndrew 2016 - Forum software by © MyBB