Hello all friends , today i am disclosing the issue which i found in X3CMS ( 0.5.1 & 0.5.1.1 )
So Here Is The X3 CMS XSS And CSRF
There were two vulnerabilities ,
- 1.) CSRF
- 2.) Reflected XSS [POST]
Hello all today we will see that how we can Prevent XSS In PHP
I am posting this for newbies or fresher who are want to know about that , So here i am using a Simple PHP Code for better understanding
I am also a newby in PHP and will try my best to help you as much as i can
====================================================
<IMG STYLE=”position:absolute; TOP:100px; LEFT:500px; WIDTH:600px; HEIGHT:300px” SRC=”/wp-content/uploads/2014/06/21.jpg”>
<?php
if(isset($_GET[search]))
$display= $_GET[search];
echo “You searched for ” . $display ;
?>
<html>
<title>Testing Application of Websecgeeks</title>
<form name=”searchsomething” method=”GET” action=”xssfixing.php”>
<p>Search For Content</p><input type=”text” input name=”search”/><br><br>
<input type=”submit” input name=”submit” value=”Search Content”/>
</form>
====================================================
Here You can see we are taking an input from search field called “search” and storing the value of it into the “display” variable and using the same variable for displaying the entered text without filtration or sanitation
It is a simple sign of XSS vulnerability,
For Prevent this we can use htmlentities or htmlspecialcharactors function , Which will be nneedfulyou will know at the end
You can use
htmlentities($variablenamewhichisdisplayingtheuserinput) ,
Exa. – According to our code – htmlentities($display)
htmlspecialcharactors($variablenamewhichisdisplayingtheuserinput)
Exa. – According to our code -htmlspecialcharactors($display)
=====================================================
Lets applied this same in our code
<IMG STYLE=”position:absolute; TOP:100px; LEFT:500px; WIDTH:600px; HEIGHT:300px” SRC=”/wp-content/uploads/2014/06/21.jpg”>
<?php
if(isset($_GET[search]))
$display= $_GET[search];
echo “You searched for ” . htmlentities($display) ;
?>
<html>
<title>Testing Application of Websecgeeks</title>
<form name=”searchsomething” method=”GET” action=”xssfixing.php”>
<p>Search For Content</p><input type=”text” input name=”search”/><br><br>
<input type=”submit” input name=”submit” value=”Search Content”/>
</form>
====================================================
Step By Step Video
As you can see that we have added htmlentities function right before the $display variable to prevent XSS Attack
use htmlspecialcharactors or htmlentities function for filtration or sanitation , If your site is UTF8 encoded then you should htmlspecialcharactor function and use htmlentities is only if your pages use encodings such as ASCII or LATIN-1 instead of UTF-8.
Comment below if you feel any problem or have queries
Note – Thanks for all your feedback on facebook , this post will update soon with other techniques also , Thanks
s , Bhaiya Jis, i was quite busy in my office work and etc , thats why i was unable to write some good stuffs