Personal tools
You are here: Home wikidblog Potential XSS in PHP Sample page
« November 2008 »
Mo Tu We Th Fr Sa Su
          1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
 

Potential XSS in PHP Sample page

It has been brought to our attention by the team at ush.it that the sample.php page in our PHP Network Client has code that could have been exploited via an XSS attack. The sample page is not part of the network client itself, it is just provided as an example of how to add two-factor authentication to PHP applications.

We've touched base with the Enterprise users that we know have used WiKID in their PHP applications. So far, no one has used that code. Rather, they have taken their existing authentication pages and added the WiKID code to bring two-factor authentication into the mix.

More information on the code in question can be found here

Updated: Corrected link.

Add comment

You can add a comment by filling out the form below. Plain text formatting. Comments and Trackbacks are moderated.

(Required)
(Required)
(Required)
(Required)
This helps us prevent automated spamming.