<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=CRV2_RevCodeReflectedAntiPatternPHP</id>
		<title>CRV2 RevCodeReflectedAntiPatternPHP - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=CRV2_RevCodeReflectedAntiPatternPHP"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=CRV2_RevCodeReflectedAntiPatternPHP&amp;action=history"/>
		<updated>2026-04-30T09:13:05Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=CRV2_RevCodeReflectedAntiPatternPHP&amp;diff=161088&amp;oldid=prev</id>
		<title>Abbas Naderi: reflected XSS attacks</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=CRV2_RevCodeReflectedAntiPatternPHP&amp;diff=161088&amp;oldid=prev"/>
				<updated>2013-10-18T19:33:21Z</updated>
		
		<summary type="html">&lt;p&gt;reflected XSS attacks&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;To mitigate reflected XSS attacks fully, a PHP code should never output variables using echo, print and other output generating functions. If the output needs to be complex (for example a HTML list of variables) the HTML part should be outside PHP tags, and the rest should be inside and using safe output functions (available in OWASP PHP Security Project Core Library). For example:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
   foreach ($list as $item)&lt;br /&gt;
   {&lt;br /&gt;
   ?&amp;gt;&lt;br /&gt;
   &amp;lt;li&amp;gt;&amp;lt;?php phpsec\exho($item);?&amp;gt;&amp;lt;/li&amp;gt;&lt;br /&gt;
   &amp;lt;?php&lt;br /&gt;
   }&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Or&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
   foreach ($list as $item)&lt;br /&gt;
   {&lt;br /&gt;
      phpsec\printf(&amp;quot;&amp;lt;li&amp;gt;%s&amp;lt;/li&amp;gt;\n&amp;quot;,$item);&lt;br /&gt;
   }&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;/div&gt;</summary>
		<author><name>Abbas Naderi</name></author>	</entry>

	</feed>