how to fix XSS Reflected in java -
i got fortify report shows xss reflected defect below 2nd line.
string name = request.getparameter("name");
response.getwriter().write("name: " + name);
recommendation given: user input displayed web clients should html encoded , validated. java code , not sure how fix this.
a simple way, can use owasp enterprise security api (java edition) :
string safe = esapi.encoder().encodeforhtml( request.getparameter( "input" ) );
see link:
Comments
Post a Comment