Is my site safe from XSS if I replace all '<' with '& lt;'?

I am wondering what is the minimum size to make a site safe from XSS .

If I just replaced <with &lt;in all the content submitted by the user, will my site be XSS safe ?

+5
source share
5 answers

It depends on the context.

In addition, coding is less than just a flash of ideas. You should simply encode all characters that have special meaning and can be used for XSS ...

  • <
  • >
  • "
  • '
  • &

, , , - ...

. .

...

http://www.example.com" onclick="window.location = 'http://nasty.com'; return false;

, , ...

<a href="http://www.example.com" onclick="window.location = 'http://nasty.com'; return false;">View user website</a>

, .

+5

. , .

+2

. , -, , - , !

, , ..Net , - ( , ) ( , "" , )

+2

, .

, . .

0
source

All Articles