Jump to content
  • Checkout
  • Login
  • Get in touch

osCommerce

The e-commerce.

XSS on create_account_process.php


stevenswing

Recommended Posts

Posted

Currently, users are able to insert IFRAMES and other code into the create_account_process.php script. This displays when they submit the form. I currently have XSS protection in the .htaccess, however this does not sanitize posted data, only the query string. Is there any site-wide mod I could apply to filter user input?

 

Thank you for your help.

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...