Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 830519
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 15, 20262026-05-15T04:03:26+00:00 2026-05-15T04:03:26+00:00

So, members of my website can post topics, replies, comments, edit them and so

  • 0

So, members of my website can post topics, replies, comments, edit them and so on. I always use htmlspecialchars and addslashes for html inputs to protect my site against XSS and SQL injection attacks. Is it enough or is there something more I miss?
Thanks.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-15T04:03:26+00:00Added an answer on May 15, 2026 at 4:03 am

    There is a lot that can go wrong with a web application. Other than XSS and SQLi, there is:

    1. CSRF – Cross Site Request Forgery
    2. LFI/RFI – Local File Include/Remote File Include caused by include(), require()…
    3. CRLF injection in mail()
    4. Global Variable Namespace Poising commonly caused by register_globals,extract(), import_request_variables()
    5. Directory Traversal: fopen(), file_get_contents(), file_put_conents()
    6. Remote Code Execution with eval() or preg_replace() with /e
    7. Remote Code Execution with passthru(), exec(), system() and “

    There is a whole family of vulnerabilities regarding Broken Authentication and Session Management which is apart of the OWASP Top 10 that every web app programmer must read.

    A Study In Scarlet is a good black paper that goes over many of these vulnerabilities that I have listed.

    However, there are also strange vulnerabilities like this one in WordPress. The definitive authority on what is a vulnerability is the CWE system which classifies HUNDREDS of vulnerabilities, many of which can affect web applications.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I let my members of my website to post some information about them in
I'm working on a website where members can post their own adsense banners onto
I am adding a functionality to a website so that members can upload there
Our company has an existing membership model that we use for our website. Members
I have an image gallery which website members can upload images to. When an
The website I am working on provides a service, where only members can get
I am creating a website where members of the family can book a vacation
Respected Members, I am designing the website in pure HTML with the help of
Okay, so here's my problem: I have a list of members on a website,
A number of team members update a central ASP.NET dev Website project, not a

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.