[nycphp-talk] wonderful presentation on Tuesday

Susan Shemin susan_shemin at
Thu Apr 26 17:19:17 EDT 2007

That makes sense with database data, but how about "hijacking" the submit button by putting their script on the button/image that sends the login info to a different domain site?

I'm not really looking for a specific how it's done (of course), but more for how ever is it possible if the webpage code is in a secure place?

----- Original Message ----
From: Rob Marscher <rmarscher at>
To: NYPHP Talk <talk at>
Sent: Thursday, April 26, 2007 4:43:48 PM
Subject: Re: [nycphp-talk] wonderful presentation on Tuesday

How ever can someone inject their code/script onto my webpage?  The code is on my server so they don't have access to it.  Am I missing something here?

If you allow the user to submit anything that is then displayed our your site, they can inject javascript code unless you do a very good job "sanitizing" the user input.

New York PHP Community Talk Mailing List

NYPHPCon 2006 Presentations Online

Show Your Participation in New York PHP
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <>

More information about the talk mailing list