Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6070067
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 23, 20262026-05-23T09:53:28+00:00 2026-05-23T09:53:28+00:00

Which of the two is a better way to prevent an xss attack? HTMLEntities

  • 0

Which of the two is a better way to prevent an xss attack?

  1. HTMLEntities while saving in db
  2. HTMLEntities while displaying/echoing

I find the first one better because you may forget to add this while displaying.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-23T09:53:29+00:00Added an answer on May 23, 2026 at 9:53 am

    which of the two is a better way to prevent xss attack.

    1. HTMLEntities while saving in db
    2. HTMLEntities while displaying/echoing

    2 — you should convert to the target format at the last possible moment. This saves you from problems down the road should you, for example, decide you want to use the same content in an email, a PDF, as text back to the user for editing, etc, etc.

    i find the first one better coz you may forget to add this while displaying

    You might forget when inserting into the database too.

    Also, not all data goes into the database. e.g. A preview of data about to be inserted or data put back into a form because of errors are both possible XSS vectors. You don’t want to be dealing with things like “Encode before putting into the database, or when echoing back into the document if it didn’t come from a database”. Exceptions are the best way to get yourself into a situation where you forget to encode.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Which of these two platforms/ecosystems are better for writing web applications/websites? I am not
Which of these two statements is faster/better practice? myList.Where(x => { bool itemOne= x.ItemOne
I have a main div which contains two divs. One for main content and
I have created a form on which two components are present, button and progressbar
I would like to match a pattern in which two words must be present,
So, I currently am working on a project, in which two different datasources will
I have two views each of which contain two subviews. Hit detection is working
I have a function which takes two arguments, the ID of an item (wine)
I have a query which returns two rows of data as count. I want
I have a view which has two labels. When I swipe left I fill

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.