Closed ad-m closed 8 years ago
I do not understand why you call me.
@mik-laj , I don't understand what do you want here. I hope that helped.
hey @ad-m the idea of this application is to understand XSS issues, try exploit them, and see what went wrong in the code. It's basically an application that can help security enthusiast to learn application security. I appreciate your intention though. Would be great if you want to write a simple blog post, how you observe the bad code here, exploited the it, and fixed the same ;)
Hello,
I am would like recommend to fix Stored Cross Site Scripting flaw.
Stored Cross Site Scripting attacks happen when the application doesn’t validate user inputs against malicious scripts, and it occurs when these scripts get stored on the database. Victim gets infected when they visit web page that loads these malicious scripts from database. For instances, message forum, comments page, visitor logs, profile page, etc.
Read more about Stored XSS: https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)#Stored_XSS_Attacks
I am glad that I helped to make web more secure. Merge please.
Greetings,