php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #62434 Bad practice escaping example in 'PHP and HTML' FAQ
Submitted: 2012-06-27 18:23 UTC Modified: 2012-06-28 00:35 UTC
From: timf at tfountain dot co dot uk Assigned: aharvey (profile)
Status: Closed Package: Documentation problem
PHP Version: Irrelevant OS:
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: timf at tfountain dot co dot uk
New email:
PHP Version: OS:

 

 [2012-06-27 18:23 UTC] timf at tfountain dot co dot uk
Description:
------------
The very first code example in the "PHP and HTML" FAQ 
(http://www.php.net/manual/en/faq.html.php) includes this code sample:

<?php
    echo "<input type='hidden' value='" . htmlspecialchars($data) . "' />\n";
?>

This code would be vulnerable to XSS if the input type was anything other than 
'hidden', since the value attribute is single quoted and htmlspecialchars does 
not escape single quotes by default. Even the hidden input would be vulnerable 
in some older browsers that allow repeating the type attribute (allowing XSS 
with something like $data = "' onmouseover='alert(document.cookie); 
type='text";).

Since this FAQ is meant to show users how to include PHP variables in a HTML 
page it would seem like a good place encourage good escaping practices. I would 
suggest this example is at least changed to:

<?php
    echo '<input type="hidden" value="' . htmlspecialchars($data) . '" />';
?>

but this section of the FAQ might also benefit from some "how do I prevent 
cross-site scripting" examples.


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2012-06-28 00:35 UTC] aharvey@php.net
Automatic comment from SVN on behalf of aharvey
Revision: http://svn.php.net/viewvc/?view=revision&amp;revision=326363
Log: Fix doc bug #62434 (Bad practice escaping example in 'PHP and HTML' FAQ).
 [2012-06-28 00:35 UTC] aharvey@php.net
-Status: Open +Status: Closed -Assigned To: +Assigned To: aharvey
 [2012-06-28 00:35 UTC] aharvey@php.net
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.

Thank you for the report, and for helping us make our documentation better.

Great catch. Thanks!
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Thu Oct 08 09:00:02 2026 UTC