Acunetix扫描提示‘输入被反射到标签参数双引号间’含义咨询
Hey there! Let me break down what this Acunetix alert means for your verif.php page, and why you might be struggling to reproduce it.
Acunetix flagged a potential issue where the afficher_forgot_password GET parameter is being reflected directly into an HTML tag's attribute value, sandwiched between double quotes on your page. Let's unpack the test payload they used to detect this:
Oui"sTYLe='acu:Expre/**/SSion(Afih(9717))'bad="
The critical piece here is the " immediately after Oui — this is designed to close the original double-quoted attribute where your parameter's value gets inserted. Once that quote is closed, the payload attempts to add a malicious style attribute using an old CSS expression trick (a common vector for XSS in older browsers).
At its core, this is a potential reflected XSS vulnerability. If an attacker crafts a similar malicious payload, they could inject arbitrary HTML or JavaScript into the page for anyone who clicks their manipulated link—assuming your code doesn't properly sanitize or escape the input before rendering it in the HTML.
There are a few common reasons you can't see the effect of the payload:
- Browser Compatibility: The payload uses
acu:Expre/**/SSion, an obfuscated version of the IE-specificexpression()CSS feature. Modern browsers (even the Chrome 73 used in the scan, let alone newer versions) block or ignore these outdated malicious CSS tricks. So even if the injection is happening, your browser won't execute it, making it invisible to you. - Request Context Matters: The
afficher_forgot_passwordparameter might only be reflected under specific conditions—like when the user is logged out, or when themembreparameter is empty (which it was in Acunetix's test request). Double-check that you're testing with the exact same context: same cookies, samelang_abbreviation=envalue, and an emptymembreparameter. - Partial Sanitization: Your server might be doing basic sanitization that blocks obvious payloads but misses the exact one Acunetix used. For example, it might strip
<script>tags but fail to escape double quotes in attribute values. The Acunetix payload uses a CSS-based attack that could slip through this minimal protection.
Instead of waiting for a visible effect from the malicious payload, manually check if your input is being rendered without proper escaping:
- Send a request like this (include your valid PHPSESSID cookie):
GET /verif.php?afficher_forgot_password=Test"Hello&lang_abbreviation=en&membre= HTTP/1.1 - View the page source and search for your input (
Test"Hello). - If you find it inside an HTML attribute like
<some-element attr="Test"Hello">, that's the red flag! The double quote from your input closed the original attribute, proving an attacker could inject their own attributes or scripts.
To patch this, you need to escape user input before inserting it into HTML attribute values. In PHP, use htmlspecialchars() with the ENT_QUOTES flag to escape both single and double quotes:
$afficher_forgot_password = htmlspecialchars($_GET['afficher_forgot_password'], ENT_QUOTES);
This converts " to ", so even if an attacker sends a quote in the parameter, it won't break the HTML attribute structure.
内容的提问来源于stack exchange,提问作者Man Of God

