Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 3800270
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 19, 20262026-05-19T13:52:00+00:00 2026-05-19T13:52:00+00:00

Ok so I just wanted to know, is this necessarily a XSS vulnerability, as

  • 0

Ok so I just wanted to know, is this necessarily a XSS vulnerability, as it does not output the results as such?

For example:

if($_GET['doRedirect'] == "yes") {
//redirect Page
} else {
//dont redirect page
}

then

http://example.com?doRedirect=yes

I have read up on all of the XSS stuff and thought I had a good understanding of it, although now im slightly confused. Is XSS only possible if the user input is then output on the page?

Many thanks 🙂

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-19T13:52:01+00:00Added an answer on May 19, 2026 at 1:52 pm

    That should be safe.

    Cross site scripting can only occur if you actually output something user-generated on your page.

    An example of this would be if you took in a user’s name as the get parameter name and did the following:

    <?php
    echo "Hello, {$_GET['name']}. How are you today?";
    ?>
    

    In this case, if someone set the name-parameter to <script>alert('Hello, There!');</script>, they’ve suddenly got some JavaScript running on an URL hosted on your domain.

    Granted, that example is pretty benign, but the fact that they could run that code means they could run any code they wished. They could, for instance, add a script that logged the usernames and passwords of all users that logged in through that URL. Your site would appear genuine, but they would have access to things they shouldn’t have.

    If you’re confused about, or interested in learning more about cross site scripting, take a look at these questions:

    • What is the general concept behind XSS?
    • What is the way(best practice) to deal with XSS?
    • How does XSS work?
    • What are the best practices for avoiding xss attacks in a PHP site
    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Just wanted to know if this function's results will always hold? private int calcHourDiff(int
I just wanted to know if I can point to class using this implementation:
Just wanted to know if i am going in the right direction or not.
I just wanted to know if this is possible. i Have a Table like
Just wanted to know if anyone is really using Objects and Collections in Oracle
Just wanted to know if there is a big chance to inject SQL While
Just wanted to know if overriding UITabBarController would get my app rejected? Is it
Just wanted to know if is possible to use mod_rewrite on a single(or more
I just wanted to know how to configure FCKEditor to upload files and images
I just wanted to know what is the main advantage of using the iterators

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.