Securing e-commerce against SQL injection, cross site scripting and broken authentication

SQLi e-commerce XSS authentication man-in- the-middle attack

Authors

  • Ng Yi Xuan School of Technology Asia Pacific University of Technology and Innovation (APU) Kuala Lumpur, Malaysia
  • Julia Juremi
    julia.juremi@staffemail.apu.edu.my
    School of Technology Asia Pacific University of Technology and Innovation (APU) Kuala Lumpur, Malaysia
  • Nurul Husna Mohd Saad School of Technology Asia Pacific University of Technology and Innovation (APU) Kuala Lumpur, Malaysia
Vol. 5 No. 2 (2021)
Original Research
January 21, 2026

Downloads

World Wide Web (WWW) has been introduced in 1980s and is widely been used until today. With WWW service, publisher able to host a website in form of hypertext using Hypertext Mark-up Language (HTML). In addition, Cascading Stylesheet (CSS) is always used with HTML to manage the layout of the webpage. Over the years, the capability of HTML and CSS is getting enhanced to create a more responsive webpage. However, all these webpages creation is more towards information sharing and does not really handle user inputs. Hence, in this project, the security measures are proposed to counter these threats will be compiled as a library to be usable in any PHP-based web application. A basic but fully functional e-commerce application is developed for the testing of the proposed security features to countermeasures the mentioned vulnerabilities.