From 3a443e9e70a413d551165a45ccdcafee7618b55c Mon Sep 17 00:00:00 2001 From: Paul Wagener Date: Fri, 25 Apr 2014 10:58:42 +0200 Subject: [PATCH] Closed body and added JS link --- templates/base.html | 2 +- templates/xss.html | 2 ++ 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/templates/base.html b/templates/base.html index a14877e..bd09523 100644 --- a/templates/base.html +++ b/templates/base.html @@ -39,5 +39,5 @@ - + diff --git a/templates/xss.html b/templates/xss.html index 7480c7c..34beb23 100644 --- a/templates/xss.html +++ b/templates/xss.html @@ -58,6 +58,8 @@ +

Op deze site kan je Javascript zonder quotejes genereren: http://jdstiles.com/java/cct.html

+
Bekijk de broncode op https://github.com/Avans/Security-Workshop/blob/master/webshop/image_zoom_escapehtml.php#L55 Voeg een simpele fix toe die dit probleem oplost. Je kan dit op twee manieren doen: 1. HTML aanpassen 2. PHP aanpassen (lees documentatie op http://php.net/htmlspecialchars )
10 punten