Search icon CANCEL
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Conferences
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
Learning Joomla! 3 Extension Development

You're reading from   Learning Joomla! 3 Extension Development If you have ideas for additional Joomla 3! features, this book will allow you to realize them. It's a complete practical guide to building and extending plugins, modules, and components. Ideal for professional developers and enthusiasts.

Arrow left icon
Product type Paperback
Published in Jul 2013
Publisher Packt
ISBN-13 9781782168379
Length 458 pages
Edition 3rd Edition
Languages
Tools
Concepts
Arrow right icon
Author (1):
Arrow left icon
Timothy John Plummer Timothy John Plummer
Author Profile Icon Timothy John Plummer
Timothy John Plummer
Arrow right icon
View More author details
Toc

Table of Contents (18) Chapters Close

Learning Joomla! 3 Extension Development
Credits
About the Author
Acknowledgement
About the Reviewers
www.PacktPub.com
Preface
1. Before you Start 2. Getting Started with Plugin Development FREE CHAPTER 3. Getting Started with Module Development 4. Getting Started with Component Development 5. Backend Component Development – Part 1 6. Backend Component Development – Part 2 7. Frontend Component Development 8. Security – Avoiding Common Vulnerabilities 9. Packing Everything Together 10. Extending your Component with Plugins and Modules Index

Cross-site scripting


Cross-site scripting (XSS) is a vulnerability that allows an attacker to insert client-side script into web pages. It can allow attackers to bypass security and execute their own code. Any input field or text area field that does not appropriately filter user input could be a potential doorway for a hacker to inject their XSS code into your website.

We can simulate this vulnerability by removing the input filtering on one of the fields in our form in the frontend updfolio view. Edit folio.xml located under /components/com_folio/models/forms and add the following highlighted code:

<field name="company" type="text" class="inputbox"
  size="40" label="COM_FOLIO_FIELD_COMPANY_LABEL"
  description="COM_FOLIO_FIELD_COMPANY_DESC" required="true" filter="raw" />

By adding the raw filter, we tell Joomla! to not filter the input and just accept it as is, which is something you wouldn't normally want to do.

Now via the updfolios view on your frontend, edit one of the records...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at €18.99/month. Cancel anytime