View Single Post
Old 01-05-2017, 12:52 AM  
deonbell
Confirmed User
 
deonbell's Avatar
 
Industry Role:
Join Date: Sep 2015
Posts: 1,045
Just like to add. If "data.html" is made up of user supplied data, make sure you filter the data so that you only get data.

To avoid problems like persistent XSS, LFI (local file inclusion), and RCE (remote code execution).
deonbell is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote