A security vulnerabililty exists in the PHAP 404 errror page in PHP that originated from the program not filtering user input. A remote attacker could exploit this vulnerability to create arbitrary script code in the browser by creating a specially crafted URL. This rule supports to defend the A6: Vulnerable and Outdated Components and A3: Injection of OWASP Top 10 - 2021. Other reference:None