There are some source code patterns for XSS I should cover
1. unserialize
1 |
|
2. String function call
1 |
|
3. call_user_func
1 |
|
4. call_user_func_array
1 |
|
5. xml template
1 | vul.php |
6. ob template
1 | vuln.php |
7. PHP_SELF
1 |
|
8. FOREACH
1 |
|
9. COOKIE
1 |
|
10. print_r
1 |
|
11. Singleton(单例模式)
1 |
|
12. type validation
1 |
|
13. string replace escape
1 |
|
14. build-in sanitize
1 |
|
1 |
|
15. vendor sanitize
1 |
|
16. List
1 |
|
17. return_by_reference
1 |
|
18. global
1 | source.php |
1 |
|
19. Field
1 | vuln.php |