XSS 08

Bookmarked!

This exercise is one of our challenges on Cross-Site Scripting

PRO Medium < 1 Hr. 9615 Essential Badge
Course

This lab demonstrates an XSS vulnerability caused by trusting user-provided paths in the <code>$_SERVER['PHP_SELF']</code> variable. It highlights how improper handling of this variable can allow attackers to inject malicious payloads into the page, even when other parts of the code are properly secured.

Injection Client Side
XSS
CWE-79
Full course content 3 videos

Ready to practice?

Get access to this lab and 600+ hands-on exercises with a PRO subscription.