If i use javascript submit()
method to submit a form, the form will only be posted with javascript enabled, but i want make sure that is actually true.
So my question is, do i need to do php validation because that might be some vulnerabilities i might not know about ? Is that enough ?
javascript submit()是否会停止php验证的必要性?
- 写回答
- 好问题 0 提建议
- 追加酬金
- 关注问题
- 邀请回答
-
5条回答 默认 最新
- douyi9787 2013-12-21 12:56关注
So my question is, do i need to do php validation because that might be some vulnerabilities i might not know about ?
Yes, you do. You can't blindly trust anything coming from the client, it can be entirely spoofed.
Off-the-cuff ways I could spoof what you're describing:
- A bookmarklet that changed form values and then did the submission
- Sending the HTTP request using curl or similar
- Using the JavaScript console to modify values before sending
I'm sure there are others.
Here's an example of just how easy the bookmarklet is:
javascript:(function(){var f=document.forms[0],e=f&&f.elements[0];if(e){e.value="My nefarious value";f.submit();}})();
That sets the value of the first element on the first form of the page to "My nefarious value" and submits the form.
本回答被题主选为最佳回答 , 对您是否有帮助呢?解决 无用评论 打赏 举报
悬赏问题
- ¥15 PointNet++的onnx模型只能使用一次
- ¥20 西南科技大学数字信号处理
- ¥15 有两个非常“自以为是”烦人的问题急期待大家解决!
- ¥30 STM32 INMP441无法读取数据
- ¥15 R语言绘制密度图,一个密度曲线内fill不同颜色如何实现
- ¥100 求汇川机器人IRCB300控制器和示教器同版本升级固件文件升级包
- ¥15 用visualstudio2022创建vue项目后无法启动
- ¥15 x趋于0时tanx-sinx极限可以拆开算吗
- ¥500 把面具戴到人脸上,请大家贡献智慧,别用大模型回答,大模型的答案没啥用
- ¥15 任意一个散点图自己下载其js脚本文件并做成独立的案例页面,不要作在线的,要离线状态。