Questions about this topic? Sign up to ask in the talk tab.
Difference between revisions of "Common language specific pitfalls"
From NetSec
(Created page with "Common language-specific pitfalls: PHP specific pitfalls: File inclusion by remote and local Situationally bad sanitizing: addslashes() htmlspecialchars() ...") |
|||
Line 1: | Line 1: | ||
− | + | =PHP specific pitfalls= | |
− | + | ==File inclusion by remote and local == | |
− | + | ==Situationally bad sanitizing== | |
− | + | ===addslashes()=== | |
− | + | ===htmlspecialchars()=== | |
− | + | ===mysql_real_escape_string()=== | |
− | + | =Perl specific pitfalls= | |
− | + | ===Command injection with open()=== | |
− | + | =Python specific pitfalls= | |
− | + | ==Urllib opens/follows file:// resource location response headers (Python)== | |
− | + | =Ruby (eruby and rails) specific pitfalls= | |
− | + | ==attr_protected== | |
− | + | ==CGI.EscapeHTML()== | |
− | + | ||
[[Category:Secure programming]] | [[Category:Secure programming]] |