[PEAR-BUG] Documentation Problem #12325 [NEW]: User note that is a documentation problem
[email protected] ("")
| Newsgroups | php.pear.doc |
|---|---|
| Message-ID | <[email protected]> |
From: wiesemann Operating system: Irrelevant Package version: PHP version: Irrelevant Package: Documentation Bug Type: Documentation Problem Bug description: User note that is a documentation problem Manual page: package.db_nestedset.php Echo\'ing $_SERVER[\'PHP_SELF\'] isn\'t a good idea: \r\nWhen a user creates a url Like \'some.host/file.php/\"><b>XSS</b><a/blabla/\', then the full Path (including unescaped HTML) will be echo\'ed.\r\nRegards -- Edit bug report at http://pear.php.net/bugs/bug.php?id=12325&edit=11 --