Securing a user input - need some confirmation


Posted on 16th Feb 2014 07:03 pm by admin

Hello All,

I am in the process of recoding a large proportion of an e-commerce site, one of the problems is that there are a few security issues floating around.

Did you know?Explore Trending and Topic pages for more stories like this.
I have a search box which was originally unprotected against XSS, I was easily able to execute JavaScript and force the system to echo out HTML *holds head in hands*.

I am using this code:

$term=preg_replace('/[^a-zA-Z0-9s]/', "", $term);

...to remove any non-alphanumeric characters (excluding spaces), I am thinking because this will strip out any characters like ', ", <, >, /, = etc, it should make my script safe again.

Can you confirm this, or is there something that I am missing?


Many thanks
No comments posted yet

Your Answer:

Login to answer
217 Like 28 Dislike
Previous forums Next forums
Other forums

To add a field on the screen XK02.
Hi All,

How to add an additional field in the vendor change control screen XK02.
The

Can I use a loop
Hi buddies!

Once again with my doubts here.

Right now I am using this sql stat

Changing files over
Just thought I'd start with the new forums looking really nice .

Ok basically I've made this

need help with php get
i have a option box that gets filled with dates, but how do i get once the option value has been cli

Port scanner problem
Hai
recently i developed one app through which u can check the opened and closed ports under an

How to kill asynchronous postback / current postback?
Hi,here is my problem:I have a web site with many pages of which some may take time to process resul

Coding question?
Hey guys, I have a quick question. If I want to make a way for people to pay for health in my game,

php global variable
how can we create global variable so we can use its value in any form.. Please give example to

Upload file and add HTML
Hey everyone,

I have a client has meeting agendas and minutes that should be posted online. I

How to refresh a parent page from a modal popup
Hi,I have a modal popup in which I need to upload a file and store in the database should give a mes

Sign up to write
Sign up now if you have flare of writing..
Login   |   Register
Follow Us
Indyaspeak @ Facebook Indyaspeak @ Twitter Indyaspeak @ Pinterest RSS



Play Free Quiz and Win Cash