We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 44195
    • 293 Posts
    Quote from: sottwell at Apr 22, 2014, 05:29 AM
    People can create pages on their machines that will send a POST to your server as if it were from your own page, but with nasty stuff in it. It is always very dangerous to use any incoming data without checking it.

    Yeah I'm stripping tags and making sure the parameter is an integer.
      I'm lead developer at Digital Penguin Creative Studio in Hong Kong. https://www.digitalpenguin.hk
      Check out the MODX tutorial series on my blog at https://www.hkwebdeveloper.com